Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Sglang CRITICAL 9.1
CVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authenticatio…

Fix: after 0.5.14
Fix from $2,300 2026-07-16
Unclassified HIGH 8.1
CVE-2026-15008

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletio…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.8
CVE-2026-47472

NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deser…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 8.4
CVE-2026-24233

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthentica…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.4
CVE-2026-24220

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauth…

Mitigation only
Fix from $1,600 2026-07-14
Tensorrt CRITICAL 9.8
CVE-2026-24227

NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability…

Fix: 11.0+
Fix from $2,300 2026-07-14
.net Framework HIGH 7.8
CVE-2026-50649

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
.net Framework HIGH 7.8
CVE-2026-50646

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Dynamics Nav CRITICAL 9.8
CVE-2026-55944

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50509

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Symfony HIGH 8.6
CVE-2026-45077

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the se…

Fix: 5.4.52 / 6.4.40+
Fix from $1,950 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Exchange Server HIGH 7.8
CVE-2026-55009

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

Fix: 15.02.2562.045+
Fix from $1,950 2026-07-14
Sql Server 2016 HIGH 8.8
CVE-2026-54117

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $1,950 2026-07-14
Sql Server 2016 HIGH 8.8
CVE-2026-54118

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $1,950 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
.net Framework HIGH 7.5
CVE-2026-50652

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 8.1
CVE-2026-12583

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unaut…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.6
CVE-2026-58233

SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when proce…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.2
CVE-2026-59521

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Rea…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-59518

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a thr…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57770

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Pho…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57744

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Them…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57724

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 8.8
CVE-2026-57713

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Even…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-57371

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15531

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function…

Patch available
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15535

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.d…

Patch available
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15529

A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py…

Patch available
Fix from $1,600 2026-07-13