Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-8751 A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod… H2o after 7402 Fix from $2,3002026-05-17 MEDIUM 6.3 CVE-2026-8735 A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the … Mitigation only Fix from $1,6002026-05-17 CRITICAL 9.8 CVE-2021-47952 python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing ma… Mitigation only Fix from $2,3002026-05-16 MEDIUM 5.3 CVE-2026-8612 WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response f… Www\ 2.00+ Fix from $1,6002026-05-15 HIGH 7.1 CVE-2026-44501 DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java ob… Datahub 1.5.0.3+ Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-1184 GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could… GitLab 18.9.7 / 18.10.6+ Fix from $1,9502026-05-14 HIGH 8.8 CVE-2026-41957 An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Softw… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 8.1 CVE-2026-7635 The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0… Patch available Fix from $1,9502026-05-13 CRITICAL 9.6 CVE-2026-34659 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit… Connect Desktop Application after 2025.8.157 Fix from $2,3002026-05-12 HIGH 8.0 CVE-2026-40368 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-35439 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-40357 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-33110 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-33112 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31237 The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset fil… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31238 The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server wit… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31239 The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hu… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31229 The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model l… Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-31232 The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) … Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31234 Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for d… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31235 The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The… Mitigation only Fix from $2,3002026-05-12 HIGH 7.8 CVE-2026-31221 PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The Lig… Pytorch Lightning after 2.6.0 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31222 The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The … Snorkel after 0.10.0 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31223 The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLab… Snorkel after 0.10.0 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31224 The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the Multita… Snorkel after 0.10.0 Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31214 The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insec… Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-31218 The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07… Mitigation only Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31219 The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07… Mitigation only Fix from $1,9502026-05-12 MEDIUM 5.1 CVE-2026-3048 An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be ab… Mitigation only Fix from $1,6002026-05-11 HIGH 7.3 CVE-2026-31253 The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnera… Mitigation only Fix from $1,9502026-05-11