Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2025-32607

Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBo…

Mitigation only
Fix from $2,300 2025-04-11
Unclassified CRITICAL 9.8
CVE-2025-32568

Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects …

Mitigation only
Fix from $2,300 2025-04-11
Unclassified CRITICAL 9.8
CVE-2025-32569

Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from…

Mitigation only
Fix from $2,300 2025-04-11
Unclassified HIGH 8.8
CVE-2025-32143

Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a th…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.8
CVE-2025-32144

Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Boa…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.8
CVE-2025-32145

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro…

Mitigation only
Fix from $1,950 2025-04-10
Bentoml CRITICAL 9.8
CVE-2025-32375EPSS 50%

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure dese…

Fix: 1.4.8+
Fix from $2,300 2025-04-09
Coldfusion HIGH 8.4
CVE-2025-30285EPSS 27%

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…

Mitigation only
Fix from $1,950 2025-04-08
Coldfusion HIGH 8.4
CVE-2025-30284

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…

Mitigation only
Fix from $1,950 2025-04-08
Coldfusion CRITICAL 9.1
CVE-2025-24447

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…

Mitigation only
Fix from $2,300 2025-04-08
Sharepoint Enterprise Server HIGH 7.2
CVE-2025-29793EPSS 22%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20172+
Fix from $1,950 2025-04-08
Springboot Admin HIGH 8.8
CVE-2025-3413

A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this…

Fix: after 2017-12-26
Fix from $1,950 2025-04-08
Unclassified HIGH 7.3
CVE-2025-3425

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through …

Mitigation only
Fix from $1,950 2025-04-07
Unclassified MEDIUM 6.2
CVE-2025-2251

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. …

Patch available
Fix from $1,600 2025-04-07
Emui HIGH 7.5
CVE-2025-31175

Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.

Mitigation only
Fix from $1,950 2025-04-07
Eladmin MEDIUM 6.5
CVE-2025-3250

A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of t…

Mitigation only
Fix from $1,600 2025-04-04
Bentoml CRITICAL 9.8
CVE-2025-27520EPSS 36%

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerabilit…

Fix: after 1.4.2
Fix from $2,300 2025-04-04
Gravityzone CRITICAL 9.8
CVE-2025-2244

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on u…

Fix: 6.41.2-1+
Fix from $2,300 2025-04-04
Unclassified MEDIUM 5.3
CVE-2025-3165

A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend…

Mitigation only
Fix from $1,600 2025-04-03
Lmdeploy HIGH 7.8
CVE-2025-3162

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file…

Fix: after 0.7.1
Fix from $1,950 2025-04-03
Unclassified HIGH 8.8
CVE-2025-30889

Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial …

Mitigation only
Fix from $1,950 2025-04-03
Robot Operating System CRITICAL 9.8
CVE-2024-39780

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting…

Patch available
Fix from $2,300 2025-04-02
Unclassified CRITICAL 9.8
CVE-2025-31612

Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll cbxpoll allows Object Injection.This issue affects CBX Poll: from n/a through…

Mitigation only
Fix from $2,300 2025-04-01
Unclassified HIGH 8.8
CVE-2025-30892

Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravel…

Mitigation only
Fix from $1,950 2025-04-01
Welcart E Commerce HIGH 8.8
CVE-2025-27130

Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrar…

Fix: after 2.11.6
Fix from $1,950 2025-04-01
Parquet Java CRITICAL 9.8
CVE-2025-30065EPSS 41%

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco…

Fix: 1.15.1+
Fix from $2,300 2025-04-01
Unclassified HIGH 8.8
CVE-2025-31074

Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This issue affects Mobile DJ Mana…

Mitigation only
Fix from $1,950 2025-04-01
Sunshine Photo Cart CRITICAL 9.8
CVE-2025-31084

Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affec…

Fix: 3.4.11+
Fix from $2,300 2025-04-01
Unclassified CRITICAL 9.8
CVE-2025-31087

Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-bill…

Mitigation only
Fix from $2,300 2025-04-01
Unclassified HIGH 8.8
CVE-2025-31129

Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnera…

Patch available
Fix from $1,950 2025-03-31