Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.8
CVE-2025-54719

Deserialization of Untrusted Data vulnerability in NooTheme Yogi - Health Beauty & Yoga noo-yogi allows Object Injection.This issue affects Yogi - He…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-53242

Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1.

Mitigation only
Fix from $2,300 2025-11-06
Unclassified HIGH 8.8
CVE-2025-49386

Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue …

Mitigation only
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-49393

Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up She…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified MEDIUM 5.5
CVE-2025-48086

Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search …

Mitigation only
Fix from $1,600 2025-11-06
Dataease CRITICAL 9.8
CVE-2025-64164

Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC c…

Fix: 2.10.15+
Fix from $2,300 2025-11-06
Unclassified MEDIUM 5.6
CVE-2025-8871

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of…

Mitigation only
Fix from $1,600 2025-11-05
Unclassified HIGH 8.8
CVE-2025-64353

Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= …

Mitigation only
Fix from $1,950 2025-10-31
Cryptidy HIGH 8.8
CVE-2025-63675

cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encrypt…

Fix: after 1.2.4
Fix from $1,950 2025-10-31
Unclassified MEDIUM 5.9
CVE-2025-12058

The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local fil…

Patch available
Fix from $1,600 2025-10-29
Unclassified CRITICAL 9.0
CVE-2025-62368

Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due…

Mitigation only
Fix from $2,300 2025-10-28
Shiyi Blog CRITICAL 9.8
CVE-2025-12305

A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJ…

Fix: after 1.2.1
Fix from $2,300 2025-10-27
Unclassified CRITICAL 9.4
CVE-2025-34292

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled …

Patch available
Fix from $2,300 2025-10-27
Unclassified HIGH 8.2
CVE-2025-46183

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted …

Mitigation only
Fix from $1,950 2025-10-24
Unclassified CRITICAL 9.8
CVE-2025-62025

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8.

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-62008

Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Tab…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from …

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60232

Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affect…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-60234

Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Pro…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60238

Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a …

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60221

Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injection.This issue affects Capti…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60224

Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object Injection.This issue affects S…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60225

Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a…

Mitigation only
Fix from $2,300 2025-10-22
White Rabbit CRITICAL 9.8
CVE-2025-60226

Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This issue affects White Rabbit: from…

Fix: after 1.5.2
Fix from $2,300 2025-10-22
Everest Forms Frontend Listing CRITICAL 9.8
CVE-2025-60210

Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.…

Fix: after 1.0.5
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-60212

Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2.

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60213

Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affects Scape: from n/a through <= …

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60214

Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-60215

Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4.

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60216

Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects Addison: from n/a through < …

Mitigation only
Fix from $2,300 2025-10-22