Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Sureforms HIGH 7.5
CVE-2025-6742

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ…

Fix: 0.0.14 / 1.0.7+
Fix from $1,950 2025-07-09
Unclassified HIGH 7.3
CVE-2025-7216

A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /app…

Mitigation only
Fix from $1,950 2025-07-09
Experience Manager CRITICAL 9.8
CVE-2025-49533EPSS 52%

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbi…

Fix: after 6.5.23.0
Fix from $2,300 2025-07-08
Connect Desktop Application CRITICAL 9.6
CVE-2025-27203

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution…

Fix: 2025.5.5+
Fix from $2,300 2025-07-08
365 Apps HIGH 8.6
CVE-2025-47994

Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-07-08
Unclassified CRITICAL 9.1
CVE-2025-42980

SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when d…

Mitigation only
Fix from $2,300 2025-07-08
Unclassified CRITICAL 9.1
CVE-2025-42963

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java obj…

Mitigation only
Fix from $2,300 2025-07-08
Unclassified CRITICAL 9.1
CVE-2025-42964

SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize…

Mitigation only
Fix from $2,300 2025-07-08
Unclassified CRITICAL 9.1
CVE-2025-42966

SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization …

Mitigation only
Fix from $2,300 2025-07-08
Activereports.net CRITICAL 9.8
CVE-2025-6810

Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Mitigation only
Fix from $2,300 2025-07-07
Activereports.net CRITICAL 9.8
CVE-2025-6811

Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remo…

Mitigation only
Fix from $2,300 2025-07-07
Boyuncms MEDIUM 5.9
CVE-2025-7099

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality …

Fix: after 1.21
Fix from $1,600 2025-07-07
Unclassified HIGH 8.8
CVE-2025-52828

Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified CRITICAL 9.8
CVE-2025-49417

Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiaction allows Object Injection.T…

Mitigation only
Fix from $2,300 2025-07-04
Unclassified MEDIUM 6.5
CVE-2025-43713

ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support …

Mitigation only
Fix from $1,600 2025-07-03
Unclassified CRITICAL 10.0
CVE-2025-34067EPSS 20%

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform du…

Mitigation only
Fix from $2,300 2025-07-02
Unclassified CRITICAL 9.8
CVE-2024-13786

The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted…

Mitigation only
Fix from $2,300 2025-07-02
Forminator HIGH 8.8
CVE-2025-6464

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up…

Fix: 1.44.3+
Fix from $1,950 2025-07-02
Unclassified CRITICAL 10.0
CVE-2025-34060

A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the …

Mitigation only
Fix from $2,300 2025-07-01
Unclassified HIGH 7.8
CVE-2025-53416

Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Mitigation only
Fix from $1,950 2025-06-30
Unclassified HIGH 7.8
CVE-2025-53415

Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Mitigation only
Fix from $1,950 2025-06-30
Unclassified MEDIUM 6.0
CVE-2025-53393

In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

Patch available
Fix from $1,600 2025-06-28
Seata CRITICAL 9.8
CVE-2025-32897

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver…

Fix: 2.3.0+
Fix from $2,300 2025-06-28
Unclassified HIGH 8.8
CVE-2025-52826

Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3.

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 8.8
CVE-2025-52827

Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3.

Mitigation only
Fix from $1,950 2025-06-27
Unclassified CRITICAL 9.8
CVE-2025-52724

Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects Amwerk: from n/a through <= 1.…

Mitigation only
Fix from $2,300 2025-06-27
Unclassified CRITICAL 9.8
CVE-2025-52725

Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <…

Mitigation only
Fix from $2,300 2025-06-27
Unclassified CRITICAL 9.8
CVE-2025-28970

Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects …

Mitigation only
Fix from $2,300 2025-06-27
Llama Factory CRITICAL 9.8
CVE-2025-53002

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and…

Fix: 0.9.4+
Fix from $2,300 2025-06-26
Websphere Application Server CRITICAL 9.8
CVE-2025-36038EPSS 9%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence …

Fix: 8.5.5.28 / 9.0.5.25+
Fix from $2,300 2025-06-25