Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2026-0762 GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute… Gpt Academic Mitigation only Fix from $1,9502026-01-23 HIGH 7.8 CVE-2025-15348 Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers … Shockline Mitigation only Fix from $1,9502026-01-23 HIGH 7.8 CVE-2025-15350 Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers… Vectorstar Mitigation only Fix from $1,9502026-01-23 HIGH 7.8 CVE-2025-15351 Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers… Vectorstar Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2025-69079 Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue af… Mitigation only Fix from $2,3002026-01-22 HIGH 8.8 CVE-2025-69099 Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects North: from n/a through <= 5.… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-69035 Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental … Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-69036 Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life C… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-69002 Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through … Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-68903 Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0. Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-68899 Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= … Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-68047 Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a t… Mitigation only Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-67619 Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n… Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2025-67617 Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a t… Mitigation only Fix from $2,3002026-01-22 HIGH 8.8 CVE-2025-50004 Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from… Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-24009 Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML… Docling Core 2.48.4+ Fix from $2,3002026-01-22 MEDIUM 6.8 CVE-2026-23946 Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a … Tendenci 15.3.12+ Fix from $1,6002026-01-22 HIGH 7.5 CVE-2026-23737 seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper … Seroval 1.4.1+ Fix from $1,9502026-01-21 CRITICAL 9.8 CVE-2026-23524 Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from th… Reverb 1.7.0+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2025-56005EPSS 17% An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the… Ply No fix yet Fix from $2,3002026-01-20 HIGH 8.1 CVE-2026-0726 The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4… Mitigation only Fix from $1,9502026-01-20 MEDIUM 5.2 CVE-2026-0895 The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org… Patch available Fix from $1,6002026-01-20 CRITICAL 9.8 CVE-2023-7334 Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code exe… T\+ after 16.000.000.0283 Fix from $2,3002026-01-15 CRITICAL 9.3 CVE-2026-23746 Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 … Mitigation only Fix from $2,3002026-01-15 HIGH 7.5 CVE-2026-21226 Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. Azure Core Shared Client Library 1.38.0+ Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2026-20963 KEVEPSS 32% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20442+ Fix from $2,3002026-01-13 HIGH 7.8 CVE-2026-0859 TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized du… TYPO3 10.4.55 / 11.5.49+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2024-14021 LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk()… Llamaindex after 0.11.6 Fix from $1,9502026-01-12 HIGH 8.8 CVE-2025-69276 Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps… Dx Netops Spectrum 25.4.1+ Fix from $1,9502026-01-12 HIGH 7.8 CVE-2026-22609 Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails… Fickling 0.1.7+ Fix from $1,9502026-01-10