Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2025-71260EPSS 34% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTA… Footprints after 20.24.01.001 Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-25445 Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X… Mitigation only Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2025-60233 Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2. Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-60237 Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0. Mitigation only Fix from $2,3002026-03-19 HIGH 8.1 CVE-2026-27096 Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue af… Mitigation only Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-25873 OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar… Patch available Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-25449 Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-25769EPSS 9% Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execut… Wazuh 4.14.3+ Fix from $2,3002026-03-17 HIGH 8.8 CVE-2026-1323 The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute un… Mailqueue 0.4.5 / 0.5.2+ Fix from $1,9502026-03-17 HIGH 8.8 CVE-2025-54920EPSS 5% This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.… Spark 3.5.7+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-32355 Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a thr… Mitigation only Fix from $1,9502026-03-13 MEDIUM 6.8 CVE-2025-13913 A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious … Ignition 8.3.0+ Fix from $1,6002026-03-12 CRITICAL 9.8 CVE-2026-3059 SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat… Sglang after 0.5.9 Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3060 SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri… Sglang after 0.5.9 Fix from $2,3002026-03-12 HIGH 7.8 CVE-2026-3989 SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of … Sglang 0.5.10+ Fix from $1,9502026-03-12 MEDIUM 6.3 CVE-2026-3967 A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file a… Mitigation only Fix from $1,6002026-03-12 HIGH 8.8 CVE-2026-22248 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. Fr… Glpi 11.0.5+ Fix from $1,9502026-03-11 HIGH 8.1 CVE-2026-2626 The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated us… Mitigation only Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-26114 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server Mitigation only Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-25166 Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 MEDIUM 6.5 CVE-2026-1286 CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execu… Ecostruxure Foxboro Dcs Control Software 8.1+ Fix from $1,6002026-03-10 CRITICAL 9.8 CVE-2025-56422 A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. Limesurvey after 6.14.3 Fix from $2,3002026-03-10 HIGH 7.8 CVE-2025-11739 CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a local… Ecostruxure Power Monitoring Expert Mitigation only Fix from $1,9502026-03-10 CRITICAL 9.1 CVE-2026-27685 SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, … Mitigation only Fix from $2,3002026-03-10 HIGH 7.5 CVE-2026-2020 The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortco… Mitigation only Fix from $1,9502026-03-07 HIGH 7.2 CVE-2026-28277 LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.… Langgraph after 1.0.9 Fix from $1,9502026-03-05 HIGH 7.8 CVE-2026-27749 Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeO… Internet Security 1.1.114.3113+ Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-2599 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28105 Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a t… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28074 Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a t… Mitigation only Fix from $2,3002026-03-05