Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Devexpress CRITICAL 9.8
CVE-2023-35814

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

Fix: 21.2.12+
Fix from $2,300 2025-04-28
Devexpress CRITICAL 9.8
CVE-2023-35815

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

Fix: 21.2.12+
Fix from $2,300 2025-04-28
Jupiter X Core HIGH 8.1
CVE-2025-2105

The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of unt…

Fix: 4.8.12+
Fix from $1,950 2025-04-26
Screenconnect HIGH 7.2
CVE-2025-3935 KEV

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preser…

Fix: 25.2.4+
Fix from $1,950 2025-04-25
Unclassified HIGH 7.2
CVE-2025-46481

Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This is…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified HIGH 7.2
CVE-2025-46473

Deserialization of Untrusted Data vulnerability in Prisna Social Counter social-counter allows Object Injection.This issue affects Social Counter: fr…

Mitigation only
Fix from $1,950 2025-04-24
Nemo CRITICAL 9.8
CVE-2025-23249

NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful ex…

Fix: 25.02+
Fix from $2,300 2025-04-22
Unclassified HIGH 7.5
CVE-2025-3857

When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from …

Mitigation only
Fix from $1,950 2025-04-21
Pytorch CRITICAL 9.8
CVE-2025-32434

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd sys…

Fix: 2.6.0+
Fix from $2,300 2025-04-18
Activemq Nms Openwire CRITICAL 9.8
CVE-2025-29953

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor…

Fix: 2.1.1+
Fix from $2,300 2025-04-18
Unclassified CRITICAL 9.8
CVE-2025-39588

Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Object Injection.This issue…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.8
CVE-2025-39550

Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Injection.This issue affects Fluent…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.8
CVE-2025-39551

Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injection.This issue affects FluentBo…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified HIGH 8.8
CVE-2025-39527

Deserialization of Untrusted Data vulnerability in bestweblayout Rating by BestWebSoft rating-bws allows Object Injection.This issue affects Rating b…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified HIGH 8.8
CVE-2025-32686

Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue affects Team Members: from n/a t…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.8
CVE-2025-32658

Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects HelpGent: from n/a through <= 2…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified HIGH 8.8
CVE-2025-32662

Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified HIGH 8.8
CVE-2025-32647

Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.This issue affects Question An…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified HIGH 8.8
CVE-2025-32571

Deserialization of Untrusted Data vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Object Injection.This issue affects T…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.8
CVE-2025-32572

Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue affects Kata Plus: from n/a t…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.8
CVE-2025-27286

Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injection.This issue affects Saoshya…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.8
CVE-2025-27287

Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS Quiz: from n/a through <= 2.0…

Mitigation only
Fix from $2,300 2025-04-17
Melapress Login Security HIGH 7.2
CVE-2025-39565

Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue aff…

Fix: 2.1.1+
Fix from $1,950 2025-04-16
Unclassified MEDIUM 5.3
CVE-2025-3677

A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low…

Mitigation only
Fix from $1,600 2025-04-16
Unclassified CRITICAL 9.8
CVE-2025-30985

Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a thr…

Mitigation only
Fix from $2,300 2025-04-15
Unclassified MEDIUM 5.5
CVE-2025-3622

A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file …

Mitigation only
Fix from $1,600 2025-04-15
Unclassified MEDIUM 6.3
CVE-2025-3590

A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality.…

Mitigation only
Fix from $1,600 2025-04-14
Unclassified MEDIUM 6.2
CVE-2025-31935

Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API ma…

Mitigation only
Fix from $1,600 2025-04-11
Everest Forms CRITICAL 9.8
CVE-2025-3439

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Inje…

Fix: 3.1.2+
Fix from $2,300 2025-04-11
Unclassified HIGH 8.8
CVE-2025-31932

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Man…

Mitigation only
Fix from $1,950 2025-04-11