Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified MEDIUM 5.3
CVE-2025-4742

A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to 9024b43f091e2eb9bac65802b120c0b35f9ba856. Affected is the functi…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-4740

A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affects unknown code of the file co…

Mitigation only
Fix from $1,600 2025-05-16
Emlog CRITICAL 9.8
CVE-2025-47784

Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully craft…

Fix: 2.5.14+
Fix from $2,300 2025-05-15
Unclassified MEDIUM 5.3
CVE-2025-4701

A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.l…

Mitigation only
Fix from $1,600 2025-05-15
Unclassified CRITICAL 9.5
CVE-2025-47292

Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `Debat…

Patch available
Fix from $2,300 2025-05-14
Uncanny Automator CRITICAL 9.1
CVE-2025-3623

The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of…

Fix: 6.4.0.2+
Fix from $2,300 2025-05-14
Sharepoint Server HIGH 7.0
CVE-2025-30384

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
Sharepoint Server HIGH 7.0
CVE-2025-30378

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
Sharepoint Server HIGH 7.8
CVE-2025-30382

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
Netweaver CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…

Mitigation only
Fix from $2,300 2025-05-13
Supplier Relationship Management CRITICAL 9.8
CVE-2025-30012

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac…

Mitigation only
Fix from $2,300 2025-05-13
Unclassified MEDIUM 6.6
CVE-2025-46738

An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

Mitigation only
Fix from $1,600 2025-05-12
Dataverse CRITICAL 9.8
CVE-2025-47732

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-05-08
Unclassified HIGH 7.2
CVE-2025-47683

Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Injection.This issue affects WP Mai…

Mitigation only
Fix from $1,950 2025-05-07
Wp Crm System HIGH 7.2
CVE-2025-47629

Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Object Injection.This issue affects WP-CRM System:…

Fix: after 3.4.1
Fix from $1,950 2025-05-07
Unclassified CRITICAL 9.8
CVE-2025-0855

The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via deserialization of untrusted …

Mitigation only
Fix from $2,300 2025-05-06
Vllm HIGH 8.0
CVE-2025-30165

vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some mul…

Mitigation only
Fix from $1,950 2025-05-06
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43850

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43851

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43852

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43849

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43846

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43847

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43848

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Youkefu HIGH 8.3
CVE-2025-4260

A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the …

No fix yet
Fix from $1,950 2025-05-05
Llama Factory HIGH 7.8
CVE-2025-46567

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` scr…

Fix: 1.0.0+
Fix from $1,950 2025-05-01
Unclassified HIGH 8.8
CVE-2025-23254

NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access …

Mitigation only
Fix from $1,950 2025-05-01
Vllm CRITICAL 9.8
CVE-2025-32444

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM in…

Fix: 0.8.5+
Fix from $2,300 2025-04-30
Mailessentials HIGH 8.8
CVE-2025-34491

GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary cod…

Fix: 21.8+
Fix from $1,950 2025-04-28
Mailessentials HIGH 7.8
CVE-2025-34489

GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by…

Fix: 21.8+
Fix from $1,950 2025-04-28