Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified MEDIUM 6.4
CVE-2025-61765

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio vers…

Patch available
Fix from $1,600 2025-10-06
Transformation Extender Advanced CRITICAL 9.8
CVE-2023-49886

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa…

Mitigation only
Fix from $2,300 2025-10-06
Unclassified MEDIUM 6.3
CVE-2025-11273

A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oa…

Mitigation only
Fix from $1,600 2025-10-04
Fory CRITICAL 9.8
CVE-2025-61622EPSS 41%

Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…

Fix: after 0.12.2
Fix from $2,300 2025-10-01
Unclassified HIGH 7.3
CVE-2025-11135

A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the func…

Mitigation only
Fix from $1,950 2025-09-29
Unclassified CRITICAL 10.0
CVE-2025-58384

In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the W…

Mitigation only
Fix from $2,300 2025-09-26
Unclassified MEDIUM 6.3
CVE-2025-10975

A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.rob…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified MEDIUM 6.3
CVE-2025-10974

A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of th…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified MEDIUM 6.3
CVE-2025-10965

A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/co…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified MEDIUM 6.3
CVE-2025-10950

A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file m…

Mitigation only
Fix from $1,600 2025-09-25
Datart HIGH 8.8
CVE-2025-56816

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML …

No fix yet
Fix from $1,950 2025-09-24
Iotdb MEDIUM 5.3
CVE-2025-48459

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to…

Fix: 2.0.5+
Fix from $1,600 2025-09-24
Web Help Desk CRITICAL 9.8
CVE-2025-26399 KEVEPSS 88%

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp…

Fix: after 12.8.6
Fix from $2,300 2025-09-23
Unclassified HIGH 7.2
CVE-2025-58662

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome …

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 7.2
CVE-2025-57919

Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.This issue affects ConveyThis: …

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 7.2
CVE-2025-53465

Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This issue affects GSheets Connect…

Mitigation only
Fix from $1,950 2025-09-22
Jimureport CRITICAL 9.8
CVE-2025-10771

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnectio…

Fix: after 2.1.2
Fix from $2,300 2025-09-21
Jimureport MEDIUM 6.5
CVE-2025-10770

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of…

Fix: after 2.1.2
Fix from $1,600 2025-09-21
H2o CRITICAL 9.8
CVE-2025-10768

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB…

Fix: after 3.46.0.8
Fix from $2,300 2025-09-21
H2o CRITICAL 9.8
CVE-2025-10769

A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC…

Fix: after 3.46.0.8
Fix from $2,300 2025-09-21
H2o CRITICAL 9.8
CVE-2025-6544

A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary c…

Fix: after 3.46.0.8
Fix from $2,300 2025-09-21
Keras HIGH 7.3
CVE-2025-9906

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted…

Fix: 3.11.0+
Fix from $1,950 2025-09-19
Snipe It HIGH 8.1
CVE-2025-59713

Snipe-IT before 8.1.18 allows unsafe deserialization.

Fix: 8.1.18+
Fix from $1,950 2025-09-19
Goanywhere Managed File Transfer CRITICAL 9.8
CVE-2025-10035 KEVEPSS 100%

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

Fix: 7.6.3 / 7.8.4+
Fix from $2,300 2025-09-18
Ninja Forms CRITICAL 9.8
CVE-2025-9083

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object…

Fix: 3.11.1+
Fix from $2,300 2025-09-18
Greenshot HIGH 7.8
CVE-2025-59050

Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled data received in a WM_COPYDATA…

Fix: 1.3.301+
Fix from $1,950 2025-09-16
Jasperreports Io CRITICAL 9.8
CVE-2025-10492

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to …

Fix: after 9.0.2
Fix from $2,300 2025-09-16
Fory MEDIUM 6.5
CVE-2025-59328

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr…

Fix: 0.12.2+
Fix from $1,600 2025-09-15
Dataease CRITICAL 9.8
CVE-2025-58748

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) …

Fix: 2.10.13+
Fix from $2,300 2025-09-15
Dataease CRITICAL 9.8
CVE-2025-58046

Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to…

Fix: 2.10.13+
Fix from $2,300 2025-09-15