Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.5 CVE-2026-21619 Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api module… Rebar3 0.12.1 / 2.3.2+ Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-27776 IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is dep… Accel Platform Mitigation only Fix from $1,9502026-02-27 HIGH 8.4 CVE-2026-3071 Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when l… Mitigation only Fix from $1,9502026-02-26 HIGH 7.2 CVE-2026-28138 Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <… Mitigation only Fix from $1,9502026-02-26 HIGH 8.0 CVE-2026-27830 c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instanc… Patch available Fix from $1,9502026-02-26 MEDIUM 6.6 CVE-2026-27794 LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in … Patch available Fix from $1,6002026-02-25 CRITICAL 9.8 CVE-2026-27727 mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo… Mchange Commons Java 0.4.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-26222 Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH… Altec Doclink Mitigation only Fix from $2,3002026-02-24 HIGH 7.7 CVE-2026-21665 The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 2021.2.4 (build 4.7.3155.0011) … Mitigation only Fix from $1,9502026-02-23 HIGH 8.8 CVE-2026-25747 Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat… Camel 4.10.9 / 4.14.5+ Fix from $1,9502026-02-23 HIGH 7.5 CVE-2026-2970 A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-… Datapizza Ai No fix yet Fix from $1,9502026-02-23 MEDIUM 6.5 CVE-2026-2898 A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p… Funadmin 7.1.0+ Fix from $1,6002026-02-22 HIGH 8.1 CVE-2026-27206 Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP … Patch available Fix from $1,9502026-02-21 HIGH 8.8 CVE-2026-2036 GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute … Archiver Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-2037 GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a… Archiver Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-24892 openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Ed… Openitcockpit 5.4.0+ Fix from $1,9502026-02-20 HIGH 7.5 CVE-2026-24891 openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below c… Openitcockpit 5.4.0+ Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2026-22384 Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay … Mitigation only Fix from $2,3002026-02-20 HIGH 8.8 CVE-2026-22354 Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object In… Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-22345 Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-ga… Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-22346 Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow slider-responsive-slidesho… Mitigation only Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-69404 Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69405 Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.T… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69382 Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Th… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69370 Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <=… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69371 Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69372 Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a… Mitigation only Fix from $2,3002026-02-20 HIGH 8.8 CVE-2025-69328 Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object… Mitigation only Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-69329 Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69301 Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <=… Mitigation only Fix from $2,3002026-02-20