Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.1
CVE-2025-71345

picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71347

picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attacke…

Mitigation only
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2025-71353

picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attack…

Mitigation only
Fix from $1,950 2026-07-04
Keras CRITICAL 9.8
CVE-2026-12481

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified MEDIUM 6.9
CVE-2026-13371

An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to th…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-57677

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-57621

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 8.8
CVE-2026-56037

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.8
CVE-2026-27414

Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.8
CVE-2026-27060

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium:…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-55153

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its …

Mitigation only
Fix from $1,950 2026-07-01
Advanced Jdbc Wrapper HIGH 8.8
CVE-2026-14265

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an a…

Fix: 4.0.1+
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-51947

An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip)…

Mitigation only
Fix from $2,300 2026-07-01
Ray HIGH 8.8
CVE-2026-57516

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution …

Fix: 2.56.0+
Fix from $1,950 2026-07-01
Pacsgear CRITICAL 9.8
CVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary fil…

Fix: after 5.2.1
Fix from $2,300 2026-07-01
Pacsgear CRITICAL 9.8
CVE-2026-58127

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj a…

Fix: after 5.2.1
Fix from $2,300 2026-07-01
Mediawiki CRITICAL 9.8
CVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Imp…

Fix: 1.43.9 / 1.44.6+
Fix from $2,300 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24247

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24250

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit o…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24251

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A suc…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24240

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24243

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24244

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24245

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Unclassified HIGH 8.0
CVE-2026-10538

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-56700

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified MEDIUM 6.3
CVE-2026-55223

c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deser…

Patch available
Fix from $1,600 2026-06-30
Unclassified HIGH 8.1
CVE-2025-71349

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected ma…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.1
CVE-2025-71350

picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed und…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.1
CVE-2025-71363

picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote a…

Mitigation only
Fix from $1,950 2026-06-30