Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2025-7384

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…

Mitigation only
Fix from $2,300 2025-08-13
Web Deploy 4.0 HIGH 8.8
CVE-2025-53772EPSS 22%

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

Fix: 10.0.2001+
Fix from $1,950 2025-08-12
Sharepoint Server HIGH 8.8
CVE-2025-49712EPSS 18%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-08-12
Kanboard HIGH 7.2
CVE-2025-55010

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in t…

Fix: 1.2.47+
Fix from $1,950 2025-08-12
Unclassified HIGH 7.8
CVE-2025-40759

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (Al…

Mitigation only
Fix from $1,950 2025-08-12
Unclassified HIGH 8.2
CVE-2024-54678

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions <…

Mitigation only
Fix from $1,950 2025-08-12
Modelcache CRITICAL 9.8
CVE-2025-45146

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnera…

Fix: after 0.2.0
Fix from $2,300 2025-08-11
Keras HIGH 7.8
CVE-2025-8747

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code…

Fix: after 3.10.0
Fix from $1,950 2025-08-11
Seata CRITICAL 9.8
CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm…

Mitigation only
Fix from $2,300 2025-08-08
White Jotter HIGH 7.5
CVE-2025-8708

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeMan…

No fix yet
Fix from $1,950 2025-08-08
Unclassified HIGH 8.4
CVE-2025-54886

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not…

Patch available
Fix from $1,950 2025-08-08
Unclassified MEDIUM 5.7
CVE-2025-55136

ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.

Patch available
Fix from $1,600 2025-08-07
Harmonyos MEDIUM 5.5
CVE-2025-54640

ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen di…

No fix yet
Fix from $1,600 2025-08-06
Harmonyos MEDIUM 5.5
CVE-2025-54639

ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen di…

No fix yet
Fix from $1,600 2025-08-06
Harmonyos MEDIUM 5.5
CVE-2025-54638

Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of…

No fix yet
Fix from $1,600 2025-08-06
Harmonyos MEDIUM 5.5
CVE-2025-54620

Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-08-06
Unclassified CRITICAL 9.8
CVE-2025-50460

A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.loa…

Mitigation only
Fix from $2,300 2025-08-01
Unclassified CRITICAL 9.8
CVE-2025-50472

The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model…

Mitigation only
Fix from $2,300 2025-08-01
Secure Access HIGH 7.2
CVE-2025-49083

CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with …

Fix: 13.56+
Fix from $1,950 2025-07-31
Prestashop MEDIUM 6.5
CVE-2025-25691

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO…

No fix yet
Fix from $1,600 2025-07-30
Prestashop MEDIUM 6.5
CVE-2025-25692

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r…

No fix yet
Fix from $1,600 2025-07-30
Data Management Server Firmware CRITICAL 9.8
CVE-2025-53078

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $2,300 2025-07-29
Chancms MEDIUM 6.3
CVE-2025-8266

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArti…

Fix: 3.1.3+
Fix from $1,600 2025-07-28
Chancms CRITICAL 9.8
CVE-2025-8227

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functio…

Fix: 3.1.3+
Fix from $2,300 2025-07-27
Freescout HIGH 8.8
CVE-2025-54366

FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a …

Fix: 1.8.86+
Fix from $1,950 2025-07-26
Observability Self Hosted HIGH 7.8
CVE-2025-26397

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l…

Fix: 2025.2.1+
Fix from $1,950 2025-07-24
Unclassified MEDIUM 6.5
CVE-2025-4393

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by cr…

Mitigation only
Fix from $1,600 2025-07-24
Unclassified CRITICAL 9.3
CVE-2016-15044

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the k…

No fix yet
Fix from $2,300 2025-07-23
Poly Clariti Manager MEDIUM 5.2
CVE-2025-43489

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize…

Fix: 10.12.2+
Fix from $1,600 2025-07-23
Unclassified CRITICAL 9.8
CVE-2025-7916

WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2025-07-21