Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2026-42687 Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-39532 Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39498 Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39499 Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-39474 Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-39478 Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39481 Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39471 Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39472 Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39434 Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-27053 Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. Mitigation only Fix from $2,3002026-06-15 HIGH 8.1 CVE-2026-27333 Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-39006 An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. Mitigation only Fix from $2,3002026-06-15 HIGH 7.5 CVE-2026-11860 Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper … Mitigation only Fix from $1,9502026-06-15 HIGH 7.8 CVE-2026-12191 A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py… Mitigation only Fix from $1,9502026-06-14 HIGH 8.1 CVE-2026-50632 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-50633 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-41699 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious… Spring For Graphql 1.3.9 / 1.4.5.1+ Fix from $2,3002026-06-11 HIGH 8.8 CVE-2026-20251EPSS 19% In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22… Splunk 3.8.67 / 3.9.20+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-53435EPSS 19% In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins co… Jenkins 2.555.3 / 2.568+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-52751 Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated rem… Ghidra 12.1+ Fix from $1,9502026-06-10 HIGH 8.4 CVE-2026-10721 Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauth… Mitigation only Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2026-11815 An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary… Mitigation only Fix from $1,6002026-06-10 HIGH 8.1 CVE-2026-41731 JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr… Spring For Apache Kafka 2.8.12 / 2.9.14+ Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-41732 JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all o… Spring For Apache Pulsar 1.1.18 / 1.2.17.1+ Fix from $1,9502026-06-10 HIGH 7.2 CVE-2026-40993 An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able… Spring Security 7.0.5.1+ Fix from $1,9502026-06-10 CRITICAL 9.4 CVE-2026-44963 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. Mitigation only Fix from $2,3002026-06-09 MEDIUM 5.4 CVE-2026-48560 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.8 CVE-2026-45484EPSS 35% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-26142 Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. Nuance Powerscribe 360 Mitigation only Fix from $2,3002026-06-09