Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Seata CRITICAL 9.8
CVE-2024-47552

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.…

Fix: 2.2.0+
Fix from $2,300 2025-03-20
Applio CRITICAL 9.8
CVE-2025-27781

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inferenc…

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Applio CRITICAL 9.8
CVE-2025-27778

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remo…

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Applio CRITICAL 9.8
CVE-2025-27779

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `m…

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Applio CRITICAL 9.8
CVE-2025-27780

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in …

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Vllm CRITICAL 9.0
CVE-2025-29783

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization…

Fix: 0.8.0+
Fix from $2,300 2025-03-19
Unclassified CRITICAL 9.8
CVE-2024-13410

The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versio…

Mitigation only
Fix from $2,300 2025-03-19
Unclassified HIGH 7.3
CVE-2025-2376

A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCo…

Mitigation only
Fix from $1,950 2025-03-17
Unclassified HIGH 8.8
CVE-2025-26921

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object…

Mitigation only
Fix from $1,950 2025-03-15
Qiskit CRITICAL 9.8
CVE-2025-2000

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma…

Fix: 1.4.2+
Fix from $2,300 2025-03-14
Ciyashop CRITICAL 9.8
CVE-2024-13824

The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 …

Fix: 4.19.1+
Fix from $2,300 2025-03-14
Unclassified HIGH 7.5
CVE-2024-10942

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via dese…

Mitigation only
Fix from $1,950 2025-03-13
Automation CRITICAL 9.8
CVE-2025-27925

Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

Fix: 5.8+
Fix from $2,300 2025-03-10
Tomcat CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…

Fix: 9.0.99 / 10.1.35+
Fix from $2,300 2025-03-10
Visicut CRITICAL 9.8
CVE-2025-25940

VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.

No fix yet
Fix from $2,300 2025-03-10
Unclassified CRITICAL 9.8
CVE-2025-27816

A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deseria…

Mitigation only
Fix from $2,300 2025-03-07
Unclassified HIGH 7.2
CVE-2024-13906

The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all v…

Mitigation only
Fix from $1,950 2025-03-07
Pb Cms HIGH 7.2
CVE-2025-2043

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#theme…

Mitigation only
Fix from $1,950 2025-03-06
Unclassified HIGH 7.8
CVE-2024-12742EPSS 6%

A deserialization of untrusted data vulnerability exists in NI G Web Development Software that may result in arbitrary code execution.  Successful ex…

Mitigation only
Fix from $1,950 2025-03-06
Unclassified HIGH 8.1
CVE-2025-0956

The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via de…

Mitigation only
Fix from $1,950 2025-03-05
Unclassified CRITICAL 9.8
CVE-2024-13787

The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deser…

Mitigation only
Fix from $2,300 2025-03-05
Zoomsounds CRITICAL 9.8
CVE-2024-13777

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl…

Fix: after 6.91
Fix from $2,300 2025-03-05
Givewp CRITICAL 9.8
CVE-2025-0912

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of u…

Fix: 3.20.0+
Fix from $2,300 2025-03-04
Unclassified HIGH 8.8
CVE-2025-26999

Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.Th…

Mitigation only
Fix from $1,950 2025-03-03
Unclassified HIGH 7.2
CVE-2025-26885

Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress …

Mitigation only
Fix from $1,950 2025-03-03
Events Calendar* HIGH 8.8
CVE-2025-26967

Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issu…

Fix: 2.3.15+
Fix from $1,950 2025-03-03
Check Mk Python Api CRITICAL 9.8
CVE-2024-47092

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

Fix: 5.8.1+
Fix from $2,300 2025-03-03
Unclassified HIGH 7.2
CVE-2024-13833

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via dese…

Mitigation only
Fix from $1,950 2025-03-01
Unclassified MEDIUM 6.3
CVE-2025-0769

PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize…

Mitigation only
Fix from $1,600 2025-02-28
Tabs For Woocommerce HIGH 7.2
CVE-2024-13831

The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization o…

Mitigation only
Fix from $1,950 2025-02-28