Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2025-61880 In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. Nios after 8.6.5 Fix from $1,9502026-02-12 CRITICAL 9.3 CVE-2026-26215 manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticate… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-69872 DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can … Mitigation only Fix from $2,3002026-02-11 HIGH 8.8 CVE-2026-0910 The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untru… Mitigation only Fix from $1,9502026-02-11 MEDIUM 6.5 CVE-2026-1235 The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Obj… Mitigation only Fix from $1,6002026-02-11 CRITICAL 9.8 CVE-2026-21531 Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. Azure Conversation Authoring Client Library Mitigation only Fix from $2,3002026-02-10 HIGH 7.5 CVE-2026-21511 Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 365 Apps 16.0.19127.20518+ Fix from $1,9502026-02-10 CRITICAL 9.1 CVE-2026-25923 my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f… My Little Forum 20260208.1+ Fix from $2,3002026-02-09 HIGH 7.8 CVE-2026-25925 PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability… Powerdocu 2.4.0+ Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-2113 A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/web… Tpadmin after 1.3.12 Fix from $2,3002026-02-07 CRITICAL 10.0 CVE-2026-25632 EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to … Epyt Flow 0.16.1+ Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2020-37071 CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a … Mitigation only Fix from $2,3002026-02-03 HIGH 7.2 CVE-2026-25615 Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668. Blesta 5.13.3+ Fix from $1,9502026-02-03 HIGH 7.5 CVE-2026-25614 Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680. Blesta 5.13.2+ Fix from $1,9502026-02-03 MEDIUM 6.5 CVE-2025-70559 pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to dese… Mitigation only Fix from $1,6002026-02-03 HIGH 8.4 CVE-2025-70560 Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deseriali… Boltz Mitigation only Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-24954 Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro… Mitigation only Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-1691 A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/… Bolo Solo after 2.6.4 Fix from $1,9502026-01-30 CRITICAL 9.8 CVE-2025-61140 The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. Jsonpath Mitigation only Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2025-40551 KEVEPSS 84% SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi… Web Help Desk 2026.1+ Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2025-40553EPSS 60% SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi… Web Help Desk 2026.1+ Fix from $2,3002026-01-28 HIGH 8.8 CVE-2026-24747 PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows a… Pytorch 2.10.0+ Fix from $1,9502026-01-27 HIGH 7.8 CVE-2026-24765 PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involvi… Debian Linux 8.5.52 / 9.6.33+ Fix from $1,9502026-01-27 CRITICAL 10.0 CVE-2026-24815 Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangt… Patch available Fix from $2,3002026-01-27 HIGH 7.5 CVE-2026-23864 Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-… React 19.0.4 / 19.1.5+ Fix from $1,9502026-01-26 HIGH 7.5 CVE-2026-0772 Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Langflow Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-0773 Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0763 GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a… Gpt Academic Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0764 GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Gpt Academic Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0760 Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote… Metagpt Mitigation only Fix from $2,3002026-01-23