Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-31235 The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The… Mitigation only Fix from $2,3002026-05-12 HIGH 7.8 CVE-2026-31221 PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The Lig… Pytorch Lightning after 2.6.0 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31222 The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The … Snorkel after 0.10.0 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31223 The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLab… Snorkel after 0.10.0 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31224 The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the Multita… Snorkel after 0.10.0 Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31214 The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insec… Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-31218 The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07… Mitigation only Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-31219 The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07… Mitigation only Fix from $1,9502026-05-12 MEDIUM 5.1 CVE-2026-3048 An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be ab… Mitigation only Fix from $1,6002026-05-11 HIGH 7.3 CVE-2026-31253 The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnera… Mitigation only Fix from $1,9502026-05-11 HIGH 7.3 CVE-2026-31249 CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_… Mitigation only Fix from $1,9502026-05-11 HIGH 7.3 CVE-2026-31250 CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its avera… Mitigation only Fix from $1,9502026-05-11 HIGH 7.8 CVE-2026-7818 Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-f… Pgadmin 4 9.15+ Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-41486 Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ra… Ray Patch available Fix from $1,9502026-05-08 CRITICAL 9.2 CVE-2026-44126 SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow u… Mitigation only Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-5127 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deseria… Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.1 CVE-2025-69690 Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo… Pfsense No fix yet Fix from $2,3002026-05-08 HIGH 7.3 CVE-2024-53326 LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution. Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.3 CVE-2026-41586 Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-34084 PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3… Phpspreadsheet 1.30.3 / 2.1.15+ Fix from $2,3002026-05-05 CRITICAL 9.8 CVE-2026-42027 Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M… Opennlp 2.5.9+ Fix from $2,3002026-05-04 MEDIUM 6.3 CVE-2026-7712 A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipul… Mitigation only Fix from $1,6002026-05-04 HIGH 8.1 CVE-2026-7647 The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use… Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.3 CVE-2026-7597 A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Per… Patch available Fix from $1,6002026-05-01 HIGH 8.1 CVE-2026-42471 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data rece… Mitigation only Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-42472 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the … Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42473 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesyste… Mitigation only Fix from $2,3002026-05-01 HIGH 8.4 CVE-2026-37552 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket,… Mix Php after 2.2.17 Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-42778 The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42779 The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01