Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2025-60209

Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Objec…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60039

Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-59007

Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.Thi…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-52740

Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection.This issue affects Boldermail: fro…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-52737

Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store …

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-49380

Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This …

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-31634

Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue affects Insurance: from n/a th…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-32283

Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a …

Mitigation only
Fix from $1,950 2025-10-22
Churchcrm HIGH 8.1
CVE-2025-11938

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipul…

Fix: after 5.18.0
Fix from $1,950 2025-10-19
Registrationmagic CRITICAL 9.8
CVE-2017-20208

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Inject…

Fix: 3.7.9.3+
Fix from $2,300 2025-10-18
Flickr Gallery CRITICAL 9.8
CVE-2017-20207

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untruste…

Fix: after 1.5.2
Fix from $2,300 2025-10-18
Appointments CRITICAL 9.8
CVE-2017-20206

The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted …

Fix: after 2.2.1
Fix from $2,300 2025-10-18
Unclassified CRITICAL 9.8
CVE-2025-62515

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() …

Mitigation only
Fix from $2,300 2025-10-17
Dataease HIGH 7.5
CVE-2025-62419

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 a…

Fix: 2.10.14+
Fix from $1,950 2025-10-17
Dataease HIGH 8.8
CVE-2025-62420

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 da…

Fix: 2.10.14+
Fix from $1,950 2025-10-17
Unclassified CRITICAL 9.8
CVE-2025-49655

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a mal…

Patch available
Fix from $2,300 2025-10-17
Activemq Nms Amqp CRITICAL 9.8
CVE-2025-54539

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ …

Fix: 2.4.0+
Fix from $2,300 2025-10-16
Azure Monitor Agent HIGH 7.0
CVE-2025-59285

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.36.3+
Fix from $1,950 2025-10-14
Windows Server 2012 CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8524 / 10.0.17763.7922+
Fix from $2,300 2025-10-14
Sharepoint Server HIGH 8.8
CVE-2025-59237

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19127.20262+
Fix from $1,950 2025-10-14
Endpoint Manager HIGH 7.8
CVE-2025-11622

Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

Fix: 2024+
Fix from $1,950 2025-10-13
E107 MEDIUM 6.5
CVE-2025-61505

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previo…

Fix: after 2.3.3
Fix from $1,600 2025-10-10
Project Center CRITICAL 9.8
CVE-2025-35050

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2025-10-09
Project Center CRITICAL 9.8
CVE-2025-35051

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthentica…

Mitigation only
Fix from $2,300 2025-10-09
Uzy Ssm Mall MEDIUM 6.5
CVE-2025-60834

A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

No fix yet
Fix from $1,600 2025-10-08
Wukong Crm MEDIUM 6.5
CVE-2025-60828

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

No fix yet
Fix from $1,600 2025-10-08
Redragon Erp MEDIUM 6.5
CVE-2025-60830

redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.

No fix yet
Fix from $1,600 2025-10-08
Ilias CRITICAL 9.8
CVE-2025-11346

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such ma…

Mitigation only
Fix from $2,300 2025-10-06
Ilias CRITICAL 9.8
CVE-2025-11345

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulati…

Mitigation only
Fix from $2,300 2025-10-06
Unclassified CRITICAL 10.0
CVE-2025-10363

Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affe…

Mitigation only
Fix from $2,300 2025-10-06