Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-42687
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
Mitigation only
HIGH 8.8
CVE-2026-39532
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
Mitigation only
HIGH 7.2
CVE-2026-39498
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
Mitigation only
HIGH 7.2
CVE-2026-39499
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
Mitigation only
HIGH 8.8
CVE-2026-39474
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
Mitigation only
HIGH 8.8
CVE-2026-39478
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
Mitigation only
HIGH 7.2
CVE-2026-39481
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
Mitigation only
HIGH 7.2
CVE-2026-39471
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Mitigation only
HIGH 7.2
CVE-2026-39472
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
Mitigation only
HIGH 7.2
CVE-2026-39434
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-27053
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
Mitigation only
HIGH 8.1
CVE-2026-27333
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-39006
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
Mitigation only
HIGH 7.5
CVE-2026-11860
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper …
Mitigation only
HIGH 7.8
CVE-2026-12191
A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py…
Mitigation only
HIGH 8.1
CVE-2026-50632
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…
Cxf
4.1.7 / 4.2.2+
HIGH 8.1
CVE-2026-50633
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.8
CVE-2026-41699
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious…
Spring For Graphql
1.3.9 / 1.4.5.1+
HIGH 8.8
CVE-2026-20251EPSS 19%
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22…
Splunk
3.8.67 / 3.9.20+
HIGH 8.8
CVE-2026-53435EPSS 19%
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins co…
Jenkins
2.555.3 / 2.568+
HIGH 8.8
CVE-2026-52751
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated rem…
Ghidra
12.1+
HIGH 8.4
CVE-2026-10721
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauth…
Mitigation only
MEDIUM 5.3
CVE-2026-11815
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary…
Mitigation only
HIGH 8.1
CVE-2026-41731
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr…
Spring For Apache Kafka
2.8.12 / 2.9.14+
HIGH 8.1
CVE-2026-41732
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all o…
Spring For Apache Pulsar
1.1.18 / 1.2.17.1+
HIGH 7.2
CVE-2026-40993
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able…
Spring Security
7.0.5.1+
CRITICAL 9.4
CVE-2026-44963
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
Mitigation only
MEDIUM 5.4
CVE-2026-48560
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20384+
HIGH 8.8
CVE-2026-45484EPSS 35%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20384+
CRITICAL 9.8
CVE-2026-26142
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Nuance Powerscribe 360
Mitigation only