Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Hr Portal CRITICAL 9.8
CVE-2025-48780

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.…

Fix: after 7.3.2025.0408
Fix from $2,300 2025-06-06
Agilebpm HIGH 8.8
CVE-2025-5680

A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerabili…

Fix: after 2.5.0
Fix from $1,950 2025-06-05
Agilebpm HIGH 8.8
CVE-2025-5679

A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the functio…

Fix: after 2.5.0
Fix from $1,950 2025-06-05
Unified Contact Center Express HIGH 7.8
CVE-2025-20275

A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to e…

Mitigation only
Fix from $1,950 2025-06-04
Unified Contact Center Express HIGH 7.2
CVE-2025-20276

A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on…

Mitigation only
Fix from $1,950 2025-06-04
Chestnutcms HIGH 8.8
CVE-2025-5552

A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/g…

No fix yet
Fix from $1,950 2025-06-04
Unclassified CRITICAL 9.3
CVE-2025-48951

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure dese…

Patch available
Fix from $2,300 2025-06-03
Phpwcms HIGH 7.2
CVE-2025-5498

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/i…

Fix: 1.9.46 / 1.10.9+
Fix from $1,950 2025-06-03
Phpwcms CRITICAL 9.8
CVE-2025-5499

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the f…

Fix: 1.9.46 / 1.10.9+
Fix from $2,300 2025-06-03
Phpwcms CRITICAL 9.8
CVE-2025-5497

A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_…

Fix: 1.10.8+
Fix from $2,300 2025-06-03
Ninja Tables MEDIUM 5.6
CVE-2025-2939

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 vi…

Fix: 5.0.19+
Fix from $1,600 2025-06-03
Delmia Apriso CRITICAL 9.0
CVE-2025-5086 KEVEPSS 90%

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code executio…

Fix: after 2025
Fix from $2,300 2025-06-02
Debian Linux HIGH 8.8
CVE-2025-49113 KEVEPSS 98%

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

Fix: 1.5.10 / 1.6.11+
Fix from $1,950 2025-06-02
Adp Application Developer Platform HIGH 8.8
CVE-2025-5326

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Aff…

Mitigation only
Fix from $1,950 2025-05-29
Unclassified CRITICAL 9.8
CVE-2025-48336

Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This issue affects Course Builder:…

Mitigation only
Fix from $2,300 2025-05-29
Freescout HIGH 7.2
CVE-2025-48389

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data …

Fix: 1.8.178+
Fix from $1,950 2025-05-29
Inlong MEDIUM 6.5
CVE-2025-27522

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is…

Fix: 2.2.0+
Fix from $1,600 2025-05-28
Inlong MEDIUM 6.5
CVE-2025-27526

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability wh…

Fix: 2.2.0+
Fix from $1,600 2025-05-28
Inlong CRITICAL 9.1
CVE-2025-27528

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability …

Fix: 2.2.0+
Fix from $2,300 2025-05-28
Label Studio Ml Backend HIGH 7.8
CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. A…

Fix: after 2024-09-30
Fix from $1,950 2025-05-26
Pypickle HIGH 7.8
CVE-2025-5174

A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pyp…

Fix: 2.0.0+
Fix from $1,950 2025-05-26
Unclassified MEDIUM 5.3
CVE-2025-5148

A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is…

Patch available
Fix from $1,600 2025-05-25
Zentao CRITICAL 9.1
CVE-2025-5114

A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the fi…

No fix yet
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-48287

Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Injection.This issue affects Pix 4x…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-48289

Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issue affects Kids Planet: from n…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified HIGH 8.8
CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: …

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-47532

Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpayments-payment-gateway-for-woo…

Mitigation only
Fix from $2,300 2025-05-23
Zoomsounds CRITICAL 9.8
CVE-2025-47568

Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a t…

Fix: after 6.91
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-47530

Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a throu…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-39495

Deserialization of Untrusted Data vulnerability in BoldThemes Avantage avantage allows Object Injection.This issue affects Avantage: from n/a through…

Mitigation only
Fix from $2,300 2025-05-23