Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-65571
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
No fix yet
CRITICAL 9.8
CVE-2026-65572
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
No fix yet
CRITICAL 9.8
CVE-2026-65573
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
No fix yet
CRITICAL 9.8
CVE-2026-65574
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
No fix yet
CRITICAL 9.8
CVE-2026-65552
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
No fix yet
CRITICAL 9.8
CVE-2026-65556
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
No fix yet
HIGH 7.2
CVE-2026-65549
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
No fix yet
CRITICAL 9.8
CVE-2026-66909
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.0
CVE-2026-70426
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-2…
No fix yet
HIGH 7.6
CVE-2026-71294
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controlle…
No fix yet
HIGH 8.8
CVE-2026-71281
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py l…
No fix yet
CRITICAL 9.8
CVE-2026-61484
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As th…
Lucy
No fix yet
CRITICAL 9.8
CVE-2026-70554
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control…
No fix yet
HIGH 8.2
CVE-2026-47623
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulner…
Dynamo
after 1.1.0
CRITICAL 9.8
CVE-2026-69098
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to …
No fix yet
HIGH 7.8
CVE-2026-18642
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection.
Thi…
No fix yet
HIGH 8.1
CVE-2025-15672
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unaut…
No fix yet
HIGH 7.5
CVE-2026-3245
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
No fix yet
MEDIUM 6.6
CVE-2026-16062
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its…
No fix yet
CRITICAL 9.8
CVE-2026-68771
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to exec…
No fix yet
HIGH 7.5
CVE-2026-12720
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users ca…
No fix yet
HIGH 8.5
CVE-2026-11536
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Websphere Application Server
8.5.5.29 / 9.0.5.28+
CRITICAL 9.8
CVE-2026-15969
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…
Sglang
after 0.5.15
CRITICAL 9.8
CVE-2026-15976
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…
Sglang
after 0.5.15
CRITICAL 9.8
CVE-2026-12118
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…
Webmethods Integration
No fix yet
HIGH 7.5
CVE-2026-57859
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band d…
No fix yet
HIGH 7.5
CVE-2026-1360
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…
No fix yet
CRITICAL 9.8
CVE-2026-65883
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o…
Aimy Captcha Less Form Guard
after 20.0
CRITICAL 9.1
CVE-2026-58163
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: …
Traffic Server
9.2.15 / 10.1.4+