Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2026-74012 Editor PHP Object Injection in TaxoPress <= 3.51.0 versions. Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-73397 Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-73380 Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-73376 Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-73366 Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-73341 Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. Fix unknown Fix from $5,7502026-08-18 HIGH 7.2 CVE-2026-66620 Editor PHP Object Injection in OptionTree <= 2.7.3 versions. Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-59940 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all… Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-32470 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-32465 Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 8.0 CVE-2026-16138 In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with wr… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2024-13784 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.6 CVE-2026-10035 The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deseria… No fix yet Fix from $4,0002026-08-16 HIGH 8.8 CVE-2026-16099 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_li… No fix yet Fix from $4,9002026-08-16 HIGH 7.1 CVE-2025-7639 The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, p… No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19826 A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.3 CVE-2026-10571 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-pri… Websphere Application Server No fix yet Fix from $4,0002026-08-13 HIGH 7.2 CVE-2026-66256 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. … No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-28176 Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-28149 Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. No fix yet Fix from $5,7502026-08-13 HIGH 7.2 CVE-2026-27380 Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-67579 Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged … Ash Framework No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-73325 Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by s… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store… Airflow No fix yet Fix from $4,9002026-08-12 HIGH 7.3 CVE-2026-67260 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria… Airflow No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-59242 Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v… Airflow 3.3.1+ Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-58076 Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in… Airflow 3.3.1+ Fix from $4,9002026-08-12 MEDIUM 6.6 CVE-2026-68756 A party with write access to stored session data may affect JFrog Artifactory under specific conditions. No fix yet Fix from $4,0002026-08-12 HIGH 8.4 CVE-2026-18634 An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-48397 Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of th… Lightroom 15.5+ Fix from $4,9002026-08-11