Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.3
CVE-2025-2566

Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially craft…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 9.3
CVE-2025-25034

A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of…

No fix yet
Fix from $2,300 2025-06-20
Unclassified HIGH 8.1
CVE-2025-47771

PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in…

Patch available
Fix from $1,950 2025-06-20
Upsonic HIGH 8.0
CVE-2025-6279

A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the f…

Fix: after 0.55.6
Fix from $1,950 2025-06-19
Trend Micro Endpoint Encryption CRITICAL 9.8
CVE-2025-49213EPSS 10%

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on…

Fix: 6.0.0.4013+
Fix from $2,300 2025-06-17
Trend Micro Endpoint Encryption HIGH 8.8
CVE-2025-49214

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution o…

Fix: 6.0.0.4013+
Fix from $1,950 2025-06-17
Trend Micro Endpoint Encryption CRITICAL 9.8
CVE-2025-49217

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on…

Fix: 6.0.0.4013+
Fix from $2,300 2025-06-17
Trend Micro Endpoint Encryption CRITICAL 9.8
CVE-2025-49212EPSS 10%

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on…

Fix: 6.0.0.4013+
Fix from $2,300 2025-06-17
Apex Central CRITICAL 9.8
CVE-2025-49220

An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on …

Mitigation only
Fix from $2,300 2025-06-17
Apex Central CRITICAL 9.8
CVE-2025-49219

An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 9.8
CVE-2025-49330

Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified HIGH 7.2
CVE-2025-49331

Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue a…

Mitigation only
Fix from $1,950 2025-06-17
Unclassified CRITICAL 9.8
CVE-2025-30618

Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows Object Injection.This issue a…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 9.8
CVE-2025-31919

Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7.

Mitigation only
Fix from $2,300 2025-06-17
Unclassified HIGH 8.1
CVE-2025-24919

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and Contro…

Mitigation only
Fix from $1,950 2025-06-13
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-47166EPSS 15%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20396+
Fix from $1,950 2025-06-10
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-47163EPSS 15%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20396+
Fix from $1,950 2025-06-10
Unclassified CRITICAL 9.8
CVE-2025-49507

Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affects CozyStay: from n/a through …

Mitigation only
Fix from $2,300 2025-06-10
Kafka HIGH 8.8
CVE-2025-27818

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec…

Fix: 3.9.1+
Fix from $1,950 2025-06-10
Kafka HIGH 7.5
CVE-2025-27819

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…

Fix: after 3.3.2
Fix from $1,950 2025-06-10
Unclassified CRITICAL 9.8
CVE-2025-31398

Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative …

Mitigation only
Fix from $2,300 2025-06-09
Unclassified CRITICAL 9.8
CVE-2025-31429

Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This is…

Mitigation only
Fix from $2,300 2025-06-09
Unclassified CRITICAL 9.8
CVE-2025-31052

Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This …

Mitigation only
Fix from $2,300 2025-06-09
Unclassified CRITICAL 9.8
CVE-2025-31396

Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Busine…

Mitigation only
Fix from $2,300 2025-06-09
Unclassified HIGH 8.9
CVE-2025-49127

Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthentic…

Mitigation only
Fix from $1,950 2025-06-06
Inlong CRITICAL 9.8
CVE-2025-27531

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al…

Fix: 2.1.0+
Fix from $2,300 2025-06-06
Unclassified CRITICAL 9.8
CVE-2025-49072

Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue affects Mr. Murphy: from n/a …

Mitigation only
Fix from $2,300 2025-06-06
Sweet Dessert CRITICAL 9.8
CVE-2025-49073

Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: …

Fix: 1.1.13+
Fix from $2,300 2025-06-06
Photography HIGH 7.5
CVE-2025-47584

Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.

Fix: after 7.7.2
Fix from $1,950 2025-06-06
Unclassified HIGH 8.8
CVE-2025-39358

Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Pos…

Mitigation only
Fix from $1,950 2025-06-06