Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Websphere Application Server CRITICAL 9.8
CVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Axis2\/java CRITICAL 9.8
CVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0…

Fix: 2.0.1+
Fix from $2,300 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-11756

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Re…

No fix yet
Fix from $2,300 2026-07-28
Artifactory HIGH 8.8
CVE-2026-65617

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availabi…

Fix: 7.111.18 / 7.117.25+
Fix from $1,950 2026-07-27
Teamcity CRITICAL 9.8
CVE-2026-63077 KEVEPSS 11%

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Fix: 2025.11.7 / 2026.1.3+
Fix from $2,300 2026-07-27
Unclassified HIGH 8.8
CVE-2026-15962

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deseriali…

No fix yet
Fix from $1,950 2026-07-26
365 Copilot CRITICAL 9.9
CVE-2026-50517

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 8.7
CVE-2026-21655

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Applic…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.2
CVE-2026-65497

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65493

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-59544

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul…

No fix yet
Fix from $2,300 2026-07-23
Platform Security For Java CRITICAL 9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java CRITICAL 9.8
CVE-2026-60372

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-60373

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $1,950 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-60439

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

Mitigation only
Fix from $1,950 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-61246

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $1,950 2026-07-22
Platform Security For Java CRITICAL 10.0
CVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java CRITICAL 9.8
CVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Telerik Ui For Asp.net Ajax HIGH 8.1
CVE-2026-13185

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize…

Fix: 2026.2.708+
Fix from $1,950 2026-07-22
Telerik Ui For Asp.net Ajax HIGH 8.1
CVE-2026-13190

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation…

Fix: 2026.2.708+
Fix from $1,950 2026-07-22
Jre HIGH 7.4
CVE-2026-47058

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Dif…

No fix yet
Fix from $1,950 2026-07-21
Fory CRITICAL 9.8
CVE-2026-64606

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Fory CRITICAL 9.8
CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-63767

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers t…

No fix yet
Fix from $2,300 2026-07-20
Wazuh CRITICAL 9.1
CVE-2026-28220

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distribu…

Fix: 4.14.5+
Fix from $2,300 2026-07-20
Unclassified HIGH 7.8
CVE-2026-12484

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras…

No fix yet
Fix from $1,950 2026-07-19
Langflow CRITICAL 9.9
CVE-2026-8476

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache …

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Unclassified HIGH 8.0
CVE-2026-45162

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize…

No fix yet
Fix from $1,950 2026-07-17