Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-51744 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks. Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51745 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks. Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51746 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks. Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51743 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization att… Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51742 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter direc… Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-61168 An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file. Pmb Mitigation only Fix from $2,3002025-11-25 MEDIUM 5.5 CVE-2025-13467 A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserializa… Patch available Fix from $1,6002025-11-25 HIGH 7.2 CVE-2025-66073 Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/… Mitigation only Fix from $1,9502025-11-21 HIGH 7.2 CVE-2025-66055 Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affec… Mitigation only Fix from $1,9502025-11-21 HIGH 8.8 CVE-2025-62164 vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co… Vllm 0.11.1+ Fix from $1,9502025-11-21 CRITICAL 9.8 CVE-2025-59245 Microsoft SharePoint Online Elevation of Privilege Vulnerability Sharepoint Online No fix yet Fix from $2,3002025-11-20 HIGH 8.8 CVE-2025-36072 IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration… Webmethods Integration Mitigation only Fix from $1,9502025-11-20 MEDIUM 6.3 CVE-2025-64408EPSS 11% Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul… Causeway 3.5.0+ Fix from $1,6002025-11-19 HIGH 7.2 CVE-2025-13145 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… Mitigation only Fix from $1,9502025-11-19 HIGH 8.4 CVE-2025-60455 Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used al… Max 25.6.0+ Fix from $1,9502025-11-18 MEDIUM 5.9 CVE-2025-13081 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue… Drupal 10.4.9 / 10.5.6+ Fix from $1,6002025-11-18 HIGH 7.1 CVE-2025-12844 The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via des… Mitigation only Fix from $1,9502025-11-13 CRITICAL 9.8 CVE-2025-11367 The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization N Central 2025.4+ Fix from $2,3002025-11-12 HIGH 8.0 CVE-2025-62204 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20338+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-64512 Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107… Debian Linux 2025-11-07+ Fix from $1,9502025-11-10 MEDIUM 6.5 CVE-2025-63617 ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and… Ktg Mes 2025-10-08+ Fix from $1,6002025-11-10 HIGH 7.2 CVE-2025-12099 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up … Mitigation only Fix from $1,9502025-11-08 HIGH 7.4 CVE-2025-64439 LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2… Patch available Fix from $1,9502025-11-07 HIGH 8.8 CVE-2025-62035 Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. Mitigation only Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-60245 Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.8 CVE-2025-58998 Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a t… Mitigation only Fix from $2,3002025-11-06 HIGH 8.1 CVE-2025-58592 Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects T… Mitigation only Fix from $1,9502025-11-06 HIGH 8.8 CVE-2025-58619 Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage… Mitigation only Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-58636 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue af… Mitigation only Fix from $2,3002025-11-06 HIGH 8.8 CVE-2025-53586 Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through … Mitigation only Fix from $1,9502025-11-06