Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.1
CVE-2025-53583

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object Injection.This issue affects Em…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 8.1
CVE-2025-53584

Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Object…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 8.1
CVE-2025-53572

Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injection.This issue affects WP Easy …

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 8.1
CVE-2025-53243

Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-d…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified CRITICAL 9.8
CVE-2025-52761

Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection.This issue affects WP Funnel…

Mitigation only
Fix from $2,300 2025-08-28
Unclassified CRITICAL 10.0
CVE-2024-13980

H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xh…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified HIGH 7.2
CVE-2025-58218

Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition small-package-quotes-usps-edition allows Obj…

Mitigation only
Fix from $1,950 2025-08-27
Dataease CRITICAL 9.8
CVE-2025-57773EPSS 8%

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JN…

Fix: 2.10.12+
Fix from $2,300 2025-08-25
Adminer HIGH 8.6
CVE-2025-43960

Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:100000…

No fix yet
Fix from $1,950 2025-08-25
Mahara CRITICAL 9.8
CVE-2022-45134

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly struc…

Fix: 21.10.6 / 22.04.4+
Fix from $2,300 2025-08-22
Elite HIGH 8.8
CVE-2025-52287

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

No fix yet
Fix from $1,950 2025-08-22
Unclassified HIGH 8.7
CVE-2025-54923

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authen…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified MEDIUM 6.6
CVE-2025-54053

Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified HIGH 8.8
CVE-2025-54007

Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Po…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 7.2
CVE-2025-54012

Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Co…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-54014

Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Object Injection.This issue affe…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 8.8
CVE-2025-53560

Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.

Mitigation only
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-53299

Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This …

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-49890

Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This issue affects Organic Beauty: …

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-49434

Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue affects Cars4Rent: from n/a thr…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 8.1
CVE-2025-49438

Deserialization of Untrusted Data vulnerability in Max Chirkov Simple Login Log allows Object Injection. This issue affects Simple Login Log: from n/…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 7.5
CVE-2025-8289

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deseria…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 8.8
CVE-2025-8145

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deseria…

Mitigation only
Fix from $1,950 2025-08-20
N Central HIGH 7.8
CVE-2025-8875 KEV

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

Fix: 2025.3.1+
Fix from $1,950 2025-08-14
Jimureport CRITICAL 9.8
CVE-2025-8963

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDat…

Fix: after 2.1.1
Fix from $2,300 2025-08-14
Unclassified CRITICAL 9.8
CVE-2025-54686

Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affects Exertio: from n/a through…

Mitigation only
Fix from $2,300 2025-08-14
Unclassified HIGH 8.8
CVE-2025-49869

Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a t…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.2
CVE-2025-47536

Deserialization of Untrusted Data vulnerability in keywordrush Content Egg content-egg allows Object Injection.This issue affects Content Egg: from n…

Mitigation only
Fix from $1,950 2025-08-14
Nemo CRITICAL 9.8
CVE-2025-23303

NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code executio…

Fix: 2.3.2+
Fix from $2,300 2025-08-13
Unclassified CRITICAL 10.0
CVE-2025-34153

Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deser…

Mitigation only
Fix from $2,300 2025-08-13