Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-65571 Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65572 Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65573 Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65574 Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65552 Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65556 Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. No fix yet Fix from $2,3002026-08-06 HIGH 7.2 CVE-2026-65549 Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-28139 Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.0 CVE-2026-70426 In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-2… No fix yet Fix from $2,3002026-08-05 HIGH 7.6 CVE-2026-71294 Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controlle… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py l… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-61484 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th… Lucy No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-70554 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control… No fix yet Fix from $2,3002026-08-04 HIGH 8.2 CVE-2026-47623 NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulner… Dynamo after 1.1.0 Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-69098 kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to … No fix yet Fix from $2,3002026-08-04 HIGH 7.8 CVE-2026-18642 Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. Thi… No fix yet Fix from $1,9502026-08-03 HIGH 8.1 CVE-2025-15672 The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unaut… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-3245 A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. No fix yet Fix from $1,9502026-08-03 MEDIUM 6.6 CVE-2026-16062 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its… No fix yet Fix from $1,6002026-08-02 CRITICAL 9.8 CVE-2026-68771 ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to exec… No fix yet Fix from $2,3002026-07-31 HIGH 7.5 CVE-2026-12720 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users ca… No fix yet Fix from $1,9502026-07-31 HIGH 8.5 CVE-2026-11536 IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. Websphere Application Server 8.5.5.29 / 9.0.5.28+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-15969 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma… Sglang after 0.5.15 Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15976 SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from… Sglang after 0.5.15 Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12118 IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d… Webmethods Integration No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-57859 e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band d… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-1360 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o… Aimy Captcha Less Form Guard after 20.0 Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-58163 Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: … Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29