Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.1
CVE-2025-71344

picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, …

Mitigation only
Fix from $1,950 2026-06-22
Unclassified HIGH 8.1
CVE-2025-71358

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods.…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified CRITICAL 9.2
CVE-2026-45034

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohi…

No fix yet
Fix from $2,300 2026-06-22
Picklescan HIGH 7.8
CVE-2025-71357

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can…

Fix: 0.0.30+
Fix from $1,950 2026-06-21
Picklescan HIGH 7.8
CVE-2025-71378

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. …

Fix: 0.0.30+
Fix from $1,950 2026-06-21
Picklescan HIGH 7.8
CVE-2025-71348

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. At…

Fix: 0.0.28+
Fix from $1,950 2026-06-21
Unclassified MEDIUM 6.3
CVE-2026-12787

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part o…

Mitigation only
Fix from $1,600 2026-06-21
Picklescan MEDIUM 6.5
CVE-2026-56304

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file…

Fix: 1.0.1+
Fix from $1,600 2026-06-20
Unclassified CRITICAL 9.5
CVE-2026-48909EPSS 8%

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to …

Mitigation only
Fix from $2,300 2026-06-20
Unclassified HIGH 8.1
CVE-2026-49286

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the o…

Patch available
Fix from $1,950 2026-06-19
Pgadmin 4 CRITICAL 9.0
CVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat…

Fix: 9.16+
Fix from $2,300 2026-06-19
Geoserver HIGH 7.2
CVE-2025-27511

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extens…

Fix: 2.27.0+
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-8024

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access t…

Mitigation only
Fix from $2,300 2026-06-18
Flexplm CRITICAL 9.8
CVE-2026-12569 KEVEPSS 30%

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…

Fix: 11.0m030+
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-53805

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /…

Patch available
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval call…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-71321

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-49108

Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified HIGH 8.1
CVE-2026-40733

Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-40738

Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-40752

Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-40756

Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-40757

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39556

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39560

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39576

Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39442

Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39445

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-69127

Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified HIGH 8.8
CVE-2025-69130

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

Mitigation only
Fix from $1,950 2026-06-17