Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2025-69294 Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a thro… Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2025-68853 Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: … Mitigation only Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-68541 Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.… Mitigation only Fix from $2,3002026-02-20 HIGH 8.8 CVE-2025-68526 Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup B… Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2025-68531 Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Obje… Mitigation only Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-67997 Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-67995 Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a throu… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-67996 Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2… Mitigation only Fix from $2,3002026-02-20 HIGH 8.1 CVE-2026-27475 SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized d… Spip 4.4.9+ Fix from $1,9502026-02-19 HIGH 7.2 CVE-2026-25316 Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/… Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-23542 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Resta… Mitigation only Fix from $2,3002026-02-19 HIGH 8.8 CVE-2026-23544 Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5… Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-23549 Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro… Mitigation only Fix from $2,3002026-02-19 HIGH 7.2 CVE-2026-22333 Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affe… Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.5 CVE-2025-15579 Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote cod… Mitigation only Fix from $2,3002026-02-18 HIGH 8.8 CVE-2026-1426 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deseri… Mitigation only Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33252 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might … Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 7.3 CVE-2025-33253 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted… Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-60035 A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected.… Rexroth Indraworks 15v24+ Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-60036 A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. … Rexroth Indraworks 2.9.0 / 15v24+ Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-60037 A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a m… Rexroth Indraworks after 15v24 Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-60038 A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a m… Rexroth Indraworks after 15v24 Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33243 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit … Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-33245 NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability mig… Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33241 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successfu… Nemo 2.6.1+ Fix from $1,9502026-02-18 CRITICAL 9.3 CVE-2026-26220 LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD ma… Mitigation only Fix from $2,3002026-02-17 HIGH 7.5 CVE-2026-2555 A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/… Jeecg Boot No fix yet Fix from $1,9502026-02-16 CRITICAL 9.8 CVE-2026-26333 Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec… Verasmart 2022.0+ Fix from $2,3002026-02-13 HIGH 7.8 CVE-2026-26208 ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Cod… Patch available Fix from $1,9502026-02-13 CRITICAL 9.8 CVE-2026-26221 Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attack… Mitigation only Fix from $2,3002026-02-13