Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2026-70321 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-66808 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65815 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. Dynamics 365 No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-66805 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65663 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65665 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65658 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-64901 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-63514 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-63516 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-62912 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. Exchange Server 15.02.2562.046+ Fix from $4,0002026-08-11 CRITICAL 9.8 CVE-2026-59124 Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Windows App 2.0.1314.0+ Fix from $5,7502026-08-11 CRITICAL 10.0 CVE-2026-17061 A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthen… No fix yet Fix from $5,7502026-08-11 HIGH 8.8 CVE-2026-15555 A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River u… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.9 CVE-2026-18948 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'd… No fix yet Fix from $5,7502026-08-10 MEDIUM 5.3 CVE-2026-19363 A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.5 CVE-2026-69659 Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset paginati… Ash Framework No fix yet Fix from $4,0002026-08-09 HIGH 8.1 CVE-2026-16267 The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, al… No fix yet Fix from $1,9502026-08-08 HIGH 8.0 CVE-2026-68772 ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a sha… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2026-71558 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte… Fory 1.5.0+ Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-71559 Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying … Fory 1.5.0+ Fix from $1,9502026-08-07 CRITICAL 9.1 CVE-2026-71560 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser… Fory 1.5.0+ Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-16258 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to p… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50515 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Azure Service Bus No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-65575 Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65576 Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65577 Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65578 Unauthenticated PHP Object Injection in Agora <= 1.9 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65579 Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65581 Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. No fix yet Fix from $2,3002026-08-06