Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-27417 Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27437 Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27438 Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27439 Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <… Mitigation only Fix from $2,3002026-03-05 HIGH 8.8 CVE-2026-27379 Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.Thi… Mitigation only Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-27369 Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through <=… Mitigation only Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-27338 Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through… Mitigation only Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-27098 Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This… Mitigation only Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-23798 Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Pod… Mitigation only Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-24385 Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Po… Mitigation only Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-22474 Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22475 Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22497 Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22501 Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a thr… Mitigation only Fix from $2,3002026-03-05 HIGH 8.8 CVE-2026-22471 Deserialization of Untrusted Data vulnerability in maximsecudeal Secudeal Payments for Ecommerce secudeal-payments-for-ecommerce allows Object Inject… Mitigation only Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-22473 Deserialization of Untrusted Data vulnerability in designthemes Dental Clinic dental allows Object Injection.This issue affects Dental Clinic: from n… Mitigation only Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-22451 Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22453 Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22454 Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22417 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: fr… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-54001 Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <… Mitigation only Fix from $2,3002026-03-05 CRITICAL 10.0 CVE-2026-20131 KEVEPSS 31% A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot… Secure Firewall Management Center Mitigation only Fix from $2,3002026-03-04 HIGH 7.2 CVE-2026-3452 Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the colu… Concrete Cms 9.4.8+ Fix from $1,9502026-03-04 CRITICAL 9.8 CVE-2026-27971EPSS 5% Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ … Qwik 1.19.1+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-57622 An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_da… Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-52998 Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed.… Chamilo Lms 1.11.30+ Fix from $2,3002026-03-02 HIGH 7.2 CVE-2024-47886 Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) … Chamilo Lms 1.11.26+ Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-3422 U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary… U Office Force 29.50+ Fix from $2,3002026-03-02 HIGH 7.5 CVE-2026-2471 The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of un… Mitigation only Fix from $1,9502026-02-28 MEDIUM 6.5 CVE-2026-1542 The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object … Mitigation only Fix from $1,6002026-02-28