Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2026-25358 Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2. Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-25029 Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24. Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25030 Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25031 Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25032 Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.3… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24989 Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliat… Mitigation only Fix from $2,3002026-03-25 HIGH 8.8 CVE-2026-24978 Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a … Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-24981 Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Co… Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-24974 Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a… Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-24976 Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-24378 Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affec… Mitigation only Fix from $2,3002026-03-25 HIGH 8.1 CVE-2026-23971 Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= … Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22510 Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue affects Melody: from n/a throu… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-22500 Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 … Mitigation only Fix from $2,3002026-03-25 HIGH 8.1 CVE-2026-22505 Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Re… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-22507 Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through … Mitigation only Fix from $2,3002026-03-25 HIGH 7.2 CVE-2026-22480 Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue a… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-24159 NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might le… Nemo 2.6.2+ Fix from $2,3002026-03-24 HIGH 7.8 CVE-2026-24141 NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserializati… Mitigation only Fix from $1,9502026-03-24 HIGH 7.8 CVE-2026-24150 NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously craft… Megatron Lm 0.15.3+ Fix from $1,9502026-03-24 HIGH 7.8 CVE-2026-24151 NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously crafted inpu… Megatron Lm 0.15.3+ Fix from $1,9502026-03-24 HIGH 7.8 CVE-2026-24152 NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously craft… Megatron Lm 0.15.3+ Fix from $1,9502026-03-24 CRITICAL 9.8 CVE-2026-24157 NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of thi… Nemo 2.6.2+ Fix from $2,3002026-03-24 CRITICAL 9.0 CVE-2025-33244 NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability aff… Mitigation only Fix from $2,3002026-03-24 HIGH 7.8 CVE-2025-33247 NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of t… Megatron Lm 0.15.3+ Fix from $1,9502026-03-24 HIGH 7.8 CVE-2025-33248 NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a malicio… Megatron Lm 0.15.3+ Fix from $1,9502026-03-24 HIGH 8.7 CVE-2026-4735 Deserialization of Untrusted Data vulnerability in DTStack chunjun (‎chunjun-core/src/main/java/com/dtstack/chunjun/util modules). This vulnerability… Patch available Fix from $1,9502026-03-24 HIGH 7.8 CVE-2026-4538 A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation … Pytorch Patch available Fix from $1,9502026-03-22 MEDIUM 6.3 CVE-2026-0677 Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalCon… Mitigation only Fix from $1,6002026-03-20 HIGH 7.2 CVE-2026-29109 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain … Suitecrm 8.9.3+ Fix from $1,9502026-03-20