Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified MEDIUM 6.3
CVE-2025-10433

A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the file /admin/api/workspace/def…

Mitigation only
Fix from $1,600 2025-09-15
Unclassified HIGH 7.3
CVE-2025-10164

A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tenso…

Mitigation only
Fix from $1,950 2025-09-09
Hpc Pack CRITICAL 9.8
CVE-2025-55232

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

Fix: 6.3.8352+
Fix from $2,300 2025-09-09
Sharepoint Server HIGH 8.8
CVE-2025-54897EPSS 19%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19127.20100+
Fix from $1,950 2025-09-09
Unclassified HIGH 8.8
CVE-2025-53303

Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core:…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified HIGH 8.8
CVE-2025-48101

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant …

Mitigation only
Fix from $1,950 2025-09-09
Photography HIGH 8.1
CVE-2025-47579

Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/…

Fix: after 7.7.2
Fix from $1,950 2025-09-09
Unclassified HIGH 7.8
CVE-2025-41701

An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affec…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified CRITICAL 10.0
CVE-2025-42944

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting…

Mitigation only
Fix from $2,300 2025-09-09
Medical Open Network For Ai HIGH 8.8
CVE-2025-58756

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full…

Fix: after 1.5.0
Fix from $1,950 2025-09-09
Medical Open Network For Ai HIGH 8.8
CVE-2025-58757

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function…

Fix: after 1.5.0
Fix from $1,950 2025-09-09
Jackrabbit MEDIUM 6.5
CVE-2025-58782

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Co…

Fix: 2.22.2+
Fix from $1,600 2025-09-08
Unclassified HIGH 7.2
CVE-2025-58839

Deserialization of Untrusted Data vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Object Injection.This issue …

Mitigation only
Fix from $1,950 2025-09-05
Unclassified HIGH 7.2
CVE-2025-58815

Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon aitasi-coming-soon allows Object Injection.This issue affects Aitasi…

Mitigation only
Fix from $1,950 2025-09-05
Android HIGH 7.8
CVE-2025-48535

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywh…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32312

In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next…

Patch available
Fix from $1,950 2025-09-04
Unclassified HIGH 7.8
CVE-2025-9365

Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow …

Mitigation only
Fix from $1,950 2025-09-03
Experience Commerce CRITICAL 9.0
CVE-2025-53690 KEVEPSS 31%

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss…

Fix: after 9.0
Fix from $2,300 2025-09-03
Unclassified HIGH 7.2
CVE-2025-58643

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-quotes-daylight-edition allows…

Mitigation only
Fix from $1,950 2025-09-03
Unclassified HIGH 7.2
CVE-2025-58644

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes-tql-edition allows Object In…

Mitigation only
Fix from $1,950 2025-09-03
Unclassified HIGH 7.2
CVE-2025-58642

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight-quotes-day-ross-edition allo…

Mitigation only
Fix from $1,950 2025-09-03
Experience Commerce HIGH 8.8
CVE-2025-53691

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…

Fix: 10.4+
Fix from $1,950 2025-09-03
Freescout HIGH 8.8
CVE-2025-58163

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untruste…

Fix: 1.8.186+
Fix from $1,950 2025-09-03
Unclassified MEDIUM 6.5
CVE-2025-9260

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection…

Mitigation only
Fix from $1,600 2025-09-03
Shockline HIGH 7.8
CVE-2025-7976

Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers …

Fix: 2025.4.2+
Fix from $1,950 2025-09-02
Dasylab HIGH 7.8
CVE-2025-9188

There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successf…

Mitigation only
Fix from $1,950 2025-09-02
Unclassified CRITICAL 9.8
CVE-2025-5662

A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability a…

Patch available
Fix from $2,300 2025-09-02
Web Help Desk CRITICAL 9.8
CVE-2024-28988EPSS 39%

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…

Fix: after 12.8.2
Fix from $2,300 2025-09-01
Unclassified CRITICAL 9.8
CVE-2025-6507EPSS 14%

A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code ex…

Patch available
Fix from $2,300 2025-09-01
Unclassified HIGH 8.8
CVE-2025-54742

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro…

Mitigation only
Fix from $1,950 2025-08-28