Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2025-54719 Deserialization of Untrusted Data vulnerability in NooTheme Yogi - Health Beauty & Yoga noo-yogi allows Object Injection.This issue affects Yogi - He… Mitigation only Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-53242 Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1. Mitigation only Fix from $2,3002025-11-06 HIGH 8.8 CVE-2025-49386 Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue … Mitigation only Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-49393 Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up She… Mitigation only Fix from $2,3002025-11-06 MEDIUM 5.5 CVE-2025-48086 Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search … Mitigation only Fix from $1,6002025-11-06 CRITICAL 9.8 CVE-2025-64164 Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC c… Dataease 2.10.15+ Fix from $2,3002025-11-06 MEDIUM 5.6 CVE-2025-8871 The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of… Mitigation only Fix from $1,6002025-11-05 HIGH 8.8 CVE-2025-64353 Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= … Mitigation only Fix from $1,9502025-10-31 HIGH 8.8 CVE-2025-63675 cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encrypt… Cryptidy after 1.2.4 Fix from $1,9502025-10-31 MEDIUM 5.9 CVE-2025-12058 The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local fil… Patch available Fix from $1,6002025-10-29 CRITICAL 9.0 CVE-2025-62368 Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due… Mitigation only Fix from $2,3002025-10-28 CRITICAL 9.8 CVE-2025-12305 A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJ… Shiyi Blog after 1.2.1 Fix from $2,3002025-10-27 CRITICAL 9.4 CVE-2025-34292 Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled … Patch available Fix from $2,3002025-10-27 HIGH 8.2 CVE-2025-46183 The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted … Mitigation only Fix from $1,9502025-10-24 CRITICAL 9.8 CVE-2025-62025 Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8. Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-62008 Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Tab… Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-60228 Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from … Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-60232 Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affect… Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-60234 Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Pro… Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-60238 Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a … Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60221 Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injection.This issue affects Capti… Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60224 Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object Injection.This issue affects S… Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60225 Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a… Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60226 Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This issue affects White Rabbit: from… White Rabbit after 1.5.2 Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60210 Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.… Everest Forms Frontend Listing after 1.0.5 Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-60212 Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2. Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-60213 Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affects Scape: from n/a through <= … Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60214 Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/… Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-60215 Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4. Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-60216 Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects Addison: from n/a through < … Mitigation only Fix from $2,3002025-10-22