Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Edge Chromium HIGH 8.3
CVE-2026-58281

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-11
Spinnaker HIGH 7.5
CVE-2026-55175

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respecti…

Fix: 2025.3.4 / 2025.4.4+
Fix from $1,950 2026-07-10
Spinnaker HIGH 8.8
CVE-2026-44795

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing by…

Fix: 2025.3.3 / 2025.4.4+
Fix from $1,950 2026-07-10
Unisphere For Powermax HIGH 8.8
CVE-2026-54469

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker w…

Fix: 10.3.0.7+
Fix from $1,950 2026-07-10
Metabase HIGH 8.8
CVE-2026-59827

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances w…

Fix: 0.58.15 / 0.59.12+
Fix from $1,950 2026-07-09
Stanza HIGH 7.5
CVE-2026-54499

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza mo…

Fix: 1.12.2+
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-15105

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp …

No fix yet
Fix from $1,600 2026-07-08
Airflow CRITICAL 9.8
CVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …

Fix: 3.3.0+
Fix from $2,300 2026-07-07
Opennlp HIGH 7.3
CVE-2026-43825EPSS 9%

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu…

Mitigation only
Fix from $1,950 2026-07-06
Camel HIGH 8.8
CVE-2026-46590

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetada…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.8
CVE-2026-43867

Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel HIGH 8.1
CVE-2026-40859

Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Conte…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 8.1
CVE-2026-42527

Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components …

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 8.1
CVE-2026-43865

Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast ins…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-43866

Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the …

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Unclassified MEDIUM 5.3
CVE-2026-14723

A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the…

Patch available
Fix from $1,600 2026-07-05
Unclassified HIGH 8.2
CVE-2026-14637

A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affecte…

Patch available
Fix from $1,950 2026-07-04
Fickling HIGH 8.8
CVE-2026-14534

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in t…

Fix: after 0.1.10
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71372

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code executio…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71375

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can cr…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71356

picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71359

picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing re…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71360

picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed unde…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71362

picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can …

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71364

picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote c…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71366

picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71367

picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71369

picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, al…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71342

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71343

picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce met…

Mitigation only
Fix from $1,950 2026-07-04