Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Data Management Server Firmware CRITICAL 9.8
CVE-2025-53078

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $2,300 2025-07-29
Chancms MEDIUM 6.3
CVE-2025-8266

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArti…

Fix: 3.1.3+
Fix from $1,600 2025-07-28
Chancms CRITICAL 9.8
CVE-2025-8227

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functio…

Fix: 3.1.3+
Fix from $2,300 2025-07-27
Freescout HIGH 8.8
CVE-2025-54366

FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a …

Fix: 1.8.86+
Fix from $1,950 2025-07-26
Observability Self Hosted HIGH 7.8
CVE-2025-26397

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l…

Fix: 2025.2.1+
Fix from $1,950 2025-07-24
Unclassified MEDIUM 6.5
CVE-2025-4393

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by cr…

Mitigation only
Fix from $1,600 2025-07-24
Unclassified CRITICAL 9.3
CVE-2016-15044

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the k…

No fix yet
Fix from $2,300 2025-07-23
Poly Clariti Manager MEDIUM 5.2
CVE-2025-43489

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize…

Fix: 10.12.2+
Fix from $1,600 2025-07-23
Unclassified CRITICAL 9.8
CVE-2025-7916

WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2025-07-21
Metacrm CRITICAL 9.8
CVE-2025-7876

A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of th…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Sharepoint Server CRITICAL 9.8
CVE-2025-53770 KEVEPSS 100%

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsof…

Fix: 16.0.18526.20508+
Fix from $2,300 2025-07-20
Unclassified CRITICAL 9.8
CVE-2025-7696

The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all v…

Mitigation only
Fix from $2,300 2025-07-19
Unclassified CRITICAL 9.8
CVE-2025-7697

The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in a…

Mitigation only
Fix from $2,300 2025-07-19
Unclassified HIGH 8.8
CVE-2025-7433

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code ex…

Mitigation only
Fix from $1,950 2025-07-17
Unclassified HIGH 8.8
CVE-2025-31422

Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme visual-arts allows Object Injection.This issue a…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 9.8
CVE-2025-30973

Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This issue affects CoSchool LMS: from…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.8
CVE-2025-28961

Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Short…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.8
CVE-2025-30949

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects S…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified HIGH 8.8
CVE-2025-24777

Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7.

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.8
CVE-2025-24779

Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: from n/a through < 2.9.3.

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.2
CVE-2025-53990

Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilde…

Mitigation only
Fix from $1,950 2025-07-16
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49837

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49838

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49839

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49840

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Gpt Sovits Webui CRITICAL 9.8
CVE-2025-49841

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i…

Fix: after 20250228v3
Fix from $2,300 2025-07-15
Jre MEDIUM 5.9
CVE-2025-30761

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are…

Mitigation only
Fix from $1,600 2025-07-15
Friends HIGH 8.8
CVE-2025-7504

The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars para…

Fix: 3.5.2+
Fix from $1,950 2025-07-12
Camera Station CRITICAL 9.0
CVE-2025-30023

The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution atta…

Fix: 5.32.137 / 5.58.47195+
Fix from $2,300 2025-07-11
Camera Station Pro HIGH 7.8
CVE-2025-30025

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

Fix: 5.32.137 / 6.8.43213+
Fix from $1,950 2025-07-11