Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.3 CVE-2026-34615 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 HIGH 7.8 CVE-2026-32192 Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.41.0+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32184 Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally. Hpc Pack 6.3.8355+ Fix from $1,9502026-04-14 CRITICAL 9.6 CVE-2026-27303 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 HIGH 7.2 CVE-2026-3017 The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all ve… Mitigation only Fix from $1,9502026-04-14 CRITICAL 9.8 CVE-2026-40044 Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serializ… Mitigation only Fix from $2,3002026-04-13 HIGH 8.8 CVE-2026-33858 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit… Airflow 3.2.0+ Fix from $1,9502026-04-13 HIGH 7.8 CVE-2026-1462 A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin… Openshift Ai 2.25.7+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2026-35337 Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credential… Storm 2.8.6+ Fix from $1,9502026-04-13 HIGH 7.5 CVE-2026-25204 Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. Th… Escargot 2026-03-28+ Fix from $1,9502026-04-13 CRITICAL 9.4 CVE-2026-3199 A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with ta… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-39890 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit… Praisonai after 4.5.114 Fix from $2,3002026-04-08 HIGH 7.5 CVE-2026-23869 A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb… Mitigation only Fix from $1,9502026-04-08 HIGH 8.8 CVE-2026-32590 A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,9502026-04-08 CRITICAL 9.8 CVE-2026-3296 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untru… Mitigation only Fix from $2,3002026-04-08 HIGH 8.8 CVE-2026-3357 IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure de… Langflow 1.8.3+ Fix from $1,9502026-04-08 CRITICAL 9.8 CVE-2026-33439EPSS 10% Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Re… Openam 16.0.6+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-39324 Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu… Rack Session 2.1.2+ Fix from $2,3002026-04-07 HIGH 7.3 CVE-2026-24156 NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability mi… Data Loading Library 2.0.0+ Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-35464 pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin us… Pyload 2026-04-02+ Fix from $1,9502026-04-07 HIGH 7.8 CVE-2026-1839 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_sta… Transformers 5.0.0+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-35171 Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN… Kedro 1.3.0+ Fix from $2,3002026-04-06 MEDIUM 6.3 CVE-2026-5659 A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/d… Mitigation only Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5536 A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC s… Fedml after 0.8.9 Fix from $1,9502026-04-05 HIGH 7.0 CVE-2026-5473 A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipul… Core Flight System after 7.0.0 Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-35537 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbit… Webmail 1.5.14 / 1.6.14+ Fix from $1,9502026-04-03 CRITICAL 9.9 CVE-2026-34838 Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability i… Group Office 6.8.156 / 25.0.90+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-34877 An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session st… Mbed Tls 3.6.6+ Fix from $2,3002026-04-02 HIGH 7.2 CVE-2026-29782 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAM… Openstamanager 2.10.2+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-24165 NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh… Bionemo Framework 2026-01-21+ Fix from $1,9502026-03-31