Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-74012
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Fix unknown
CRITICAL 9.8
CVE-2026-73397
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Fix unknown
CRITICAL 9.8
CVE-2026-73380
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Fix unknown
CRITICAL 9.8
CVE-2026-73376
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Fix unknown
CRITICAL 9.8
CVE-2026-73366
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Fix unknown
CRITICAL 9.8
CVE-2026-73341
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Fix unknown
HIGH 7.2
CVE-2026-66620
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Fix unknown
CRITICAL 9.8
CVE-2026-59940
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all…
Fix unknown
CRITICAL 9.8
CVE-2026-32470
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Fix unknown
HIGH 8.8
CVE-2026-32465
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
Fix unknown
HIGH 8.0
CVE-2026-16138
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with wr…
Fix unknown
CRITICAL 9.8
CVE-2024-13784
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i…
No fix yet
MEDIUM 6.6
CVE-2026-10035
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deseria…
No fix yet
HIGH 8.8
CVE-2026-16099
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_li…
No fix yet
HIGH 7.1
CVE-2025-7639
The vulnerability, if exploited, could allow an authenticated miscreant
with "DNA Authority - Operator" privilege to tamper with serialized
data, p…
No fix yet
HIGH 7.3
CVE-2026-19826
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes…
No fix yet
MEDIUM 5.3
CVE-2026-10571
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-pri…
Websphere Application Server
No fix yet
HIGH 7.2
CVE-2026-66256
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.
This issue affects Apache Shindig: all versions.
…
No fix yet
HIGH 8.8
CVE-2026-28176
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28149
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
No fix yet
HIGH 7.2
CVE-2026-27380
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
No fix yet
HIGH 7.4
CVE-2026-67579
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged …
Ash Framework
No fix yet
HIGH 7.8
CVE-2026-73325
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by s…
No fix yet
HIGH 8.8
CVE-2026-67587
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store…
Airflow
No fix yet
HIGH 7.3
CVE-2026-67260
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria…
Airflow
No fix yet
MEDIUM 5.4
CVE-2026-59242
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v…
Airflow
3.3.1+
HIGH 8.8
CVE-2026-58076
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in…
Airflow
3.3.1+
MEDIUM 6.6
CVE-2026-68756
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
No fix yet
HIGH 8.4
CVE-2026-18634
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v…
No fix yet
HIGH 8.6
CVE-2026-48397
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of th…
Lightroom
15.5+