Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2026-39539 Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39545 Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39443 Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39446 Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.8 CVE-2026-39529 Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-27429 Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. Mitigation only Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2026-27410 Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions. Mitigation only Fix from $1,6002026-06-17 MEDIUM 6.6 CVE-2026-12115 The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions u… Mitigation only Fix from $1,6002026-06-17 HIGH 8.8 CVE-2026-12256 Contributor PHP Object Injection in Avada <= 3.15.3 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.4 CVE-2026-11857 Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the… Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.8 CVE-2025-69122 Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-69108 Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-60205 Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-35300 Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.… Weblogic Server Mitigation only Fix from $2,3002026-06-17 MEDIUM 6.8 CVE-2026-48775 LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4… Langgraph Checkpoint 4.1.1+ Fix from $1,6002026-06-16 HIGH 8.6 CVE-2026-10748 An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system comman… Mitigation only Fix from $1,9502026-06-16 HIGH 7.8 CVE-2026-24228 NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this … Nemo 2.7.3+ Fix from $1,9502026-06-16 CRITICAL 9.2 CVE-2026-48853 Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated … Patch available Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-9691 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49770 Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49781 Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49763 Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49765 Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49768 Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49769 Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49085 Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49104 Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 ve… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49105 Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49106 Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49109 Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. Mitigation only Fix from $2,3002026-06-15