Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.1 CVE-2026-45134 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith S… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.6 CVE-2026-48917 Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. Ldap after 793.v754d6b_41b_ea_4 Fix from $1,6002026-05-27 MEDIUM 6.6 CVE-2026-48919 Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. Active Directory after 2.41 Fix from $1,6002026-05-27 HIGH 8.2 CVE-2026-44843 LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths tha… Langchain 0.3.85 / 1.3.3+ Fix from $1,9502026-05-26 HIGH 7.8 CVE-2026-24162 NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exp… Transformers4rec 2026-03-11+ Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-45247 KEVEPSS 28% Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attack… Full Page Cache Warmer 1.11.12+ Fix from $2,3002026-05-26 MEDIUM 6.3 CVE-2026-9497 A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson Aut… Mitigation only Fix from $1,6002026-05-25 HIGH 7.8 CVE-2026-4372 A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerabili… Transformers 5.3.0+ Fix from $1,9502026-05-24 HIGH 8.8 CVE-2026-45659 KEVEPSS 10% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-41104 Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. Planetary Computer Mitigation only Fix from $1,9502026-05-22 HIGH 7.1 CVE-2026-9291 Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 … Mitigation only Fix from $1,9502026-05-22 CRITICAL 9.1 CVE-2026-39832 When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio… Crypto 0.52.0+ Fix from $2,3002026-05-22 HIGH 7.2 CVE-2026-8135 Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controll… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 CRITICAL 9.8 CVE-2026-48207 Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur… Fory 1.0.0+ Fix from $2,3002026-05-21 HIGH 7.8 CVE-2026-24216 NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerab… Bionemo Framework 2026-04-03+ Fix from $1,9502026-05-20 CRITICAL 9.8 CVE-2026-7637 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input i… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24163 NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful explo… Tensorrt Llm 1.2+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24142 NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability m… Tensorrt Llm 1.2+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2025-33255 NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit… Tensorrt Llm 1.2+ Fix from $2,3002026-05-20 HIGH 8.7 CVE-2026-6009 Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the aff… Mitigation only Fix from $1,9502026-05-19 CRITICAL 9.8 CVE-2026-31072 The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via In… Mitigation only Fix from $2,3002026-05-19 HIGH 7.3 CVE-2025-51427 An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mi… Patch available Fix from $1,9502026-05-19 CRITICAL 10.0 CVE-2026-43633 HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch betwe… Patch available Fix from $2,3002026-05-19 CRITICAL 9.2 CVE-2026-46725 The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated att… Mitigation only Fix from $2,3002026-05-19 HIGH 7.1 CVE-2026-8727 The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawle… Mitigation only Fix from $1,9502026-05-19 HIGH 7.6 CVE-2026-33233 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through… Mitigation only Fix from $1,9502026-05-19 HIGH 8.6 CVE-2026-26978 FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, … Patch available Fix from $1,9502026-05-18 CRITICAL 10.0 CVE-2026-45829EPSS 12% A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run… Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-7301 SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming… Sglang Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-7304 SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl… Sglang Mitigation only Fix from $2,3002026-05-18