Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-24164 NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh… Bionemo Framework 2026-01-21+ Fix from $2,3002026-03-31 HIGH 7.5 CVE-2026-34202 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction p… Zebra 4.3.0 / 6.0.1+ Fix from $1,9502026-03-31 MEDIUM 6.7 CVE-2026-4266 An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through… Fireware 12.12 / 2026.2+ Fix from $1,6002026-03-30 HIGH 7.8 CVE-2026-4416 The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a … Performance Library 25.12.31.01+ Fix from $1,9502026-03-30 CRITICAL 9.8 CVE-2026-4851 GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Ca… Grid\ after 0.127 Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-33728 dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a cus… Dd Trace Java 1.60.3+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33701 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, t… Opentelemetry Instrumentation For Java 2.26.1+ Fix from $2,3002026-03-27 HIGH 7.2 CVE-2026-33725 Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.5… Metabase 1.54.22 / 1.55.22+ Fix from $1,9502026-03-27 HIGH 7.3 CVE-2026-4860 A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file sr… Mitigation only Fix from $1,9502026-03-26 HIGH 7.2 CVE-2026-3328 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form p… Mitigation only Fix from $1,9502026-03-26 CRITICAL 9.8 CVE-2026-33942 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAut… Saloon 4.0.0+ Fix from $2,3002026-03-26 MEDIUM 5.4 CVE-2026-32508 Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a thro… Mitigation only Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-32509 Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.… Mitigation only Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-32510 Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a throug… Mitigation only Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-32511 Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7. Mitigation only Fix from $1,6002026-03-25 CRITICAL 9.8 CVE-2026-32512 Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue … Mitigation only Fix from $2,3002026-03-25 HIGH 8.8 CVE-2026-32513 Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affect… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-32502 Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects … Mitigation only Fix from $2,3002026-03-25 MEDIUM 5.4 CVE-2026-32506 Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a throug… Mitigation only Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-32507 Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < … Mitigation only Fix from $1,6002026-03-25 HIGH 8.8 CVE-2026-32484 Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-27084 Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27095 Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation a… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27082 Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a thro… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27083 Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work… Mitigation only Fix from $2,3002026-03-25 HIGH 8.8 CVE-2026-27045 Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This i… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-25429 Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a th… Mitigation only Fix from $2,3002026-03-25 HIGH 8.8 CVE-2026-25400 Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <=… Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-25359 Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < … Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-25360 Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9. Mitigation only Fix from $1,9502026-03-25