Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2025-39499

Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affects Medicare: from n/a through…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-39500

Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This issue affects Goodlayers Hos…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-39503

Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Object Injection.This issue affects Goodlayers Hotel…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-39480

Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue affects Car Dealer: from n/a t…

Mitigation only
Fix from $2,300 2025-05-23
Grand Tour CRITICAL 9.8
CVE-2025-39485

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a th…

Fix: after 5.6
Fix from $2,300 2025-05-23
Unclassified HIGH 8.8
CVE-2025-32284

Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue affects Pet World: from n/a th…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-32292

Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress jarvis allows Object Injection.This …

Mitigation only
Fix from $2,300 2025-05-23
Unclassified HIGH 8.8
CVE-2025-32293

Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consult…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified HIGH 8.8
CVE-2025-31924

Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Art…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31927

Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola: from n/a through 1.6.5.

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31423

Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affects Umberto: from n/a through …

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31430

Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31631

Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue affects Fish House: from n/a…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31069

Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotSta…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31049

Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 10.0
CVE-2025-48200

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.

Mitigation only
Fix from $2,300 2025-05-21
Unclassified HIGH 7.2
CVE-2025-4803

The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in…

Mitigation only
Fix from $1,950 2025-05-21
Vllm CRITICAL 9.8
CVE-2025-47277

vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments u…

Fix: 0.8.5+
Fix from $2,300 2025-05-20
Unclassified HIGH 7.5
CVE-2025-48018

An authenticated user can modify application state data.

No fix yet
Fix from $1,950 2025-05-20
Grand Conference CRITICAL 9.8
CVE-2025-39354

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.This issue affects Grand Confe…

Fix: after 5.3
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.8
CVE-2025-39356

Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This issue affec…

Mitigation only
Fix from $2,300 2025-05-19
Foodbakery CRITICAL 9.8
CVE-2025-32927

Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This issue affects FoodBakery: from n…

Fix: after 3.3
Fix from $2,300 2025-05-19
Altair CRITICAL 9.8
CVE-2025-32928

Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects Altair: from n/a through <= 5.…

Fix: after 5.2.2
Fix from $2,300 2025-05-19
Grand Restaurant CRITICAL 9.8
CVE-2025-39348

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Resta…

Fix: after 7.0
Fix from $2,300 2025-05-19
Ciyashop CRITICAL 9.8
CVE-2025-39349

Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop ciyashop allows Object Injection.This issue affects CiyaShop: from…

Fix: after 4.18.0
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.8
CVE-2025-47581

Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Object Injection.Thi…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.8
CVE-2025-39410

Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon.This issue affects Smart Sec…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.8
CVE-2025-47582

Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Word…

Mitigation only
Fix from $2,300 2025-05-19
Basestation CRITICAL 9.8
CVE-2025-4905

A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the …

Fix: after 3.0.4
Fix from $2,300 2025-05-19
Wp Tabs HIGH 7.2
CVE-2025-48134

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.This issue affects WP Tabs: f…

Fix: after 2.2.11
Fix from $1,950 2025-05-16