Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-60209 Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Objec… Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-60039 Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0. Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-59007 Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.Thi… Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-52740 Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection.This issue affects Boldermail: fro… Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-52737 Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store … Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-49380 Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This … Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-31634 Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue affects Insurance: from n/a th… Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-32283 Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a … Mitigation only Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-11938 A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipul… Churchcrm after 5.18.0 Fix from $1,9502025-10-19 CRITICAL 9.8 CVE-2017-20208 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Inject… Registrationmagic 3.7.9.3+ Fix from $2,3002025-10-18 CRITICAL 9.8 CVE-2017-20207 The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untruste… Flickr Gallery after 1.5.2 Fix from $2,3002025-10-18 CRITICAL 9.8 CVE-2017-20206 The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted … Appointments after 2.2.1 Fix from $2,3002025-10-18 CRITICAL 9.8 CVE-2025-62515 pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() … Mitigation only Fix from $2,3002025-10-17 HIGH 7.5 CVE-2025-62419 DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 a… Dataease 2.10.14+ Fix from $1,9502025-10-17 HIGH 8.8 CVE-2025-62420 DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 da… Dataease 2.10.14+ Fix from $1,9502025-10-17 CRITICAL 9.8 CVE-2025-49655 Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a mal… Patch available Fix from $2,3002025-10-17 CRITICAL 9.8 CVE-2025-54539 A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ … Activemq Nms Amqp 2.4.0+ Fix from $2,3002025-10-16 HIGH 7.0 CVE-2025-59285 Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.36.3+ Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-59287 KEVEPSS 100% Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8524 / 10.0.17763.7922+ Fix from $2,3002025-10-14 HIGH 8.8 CVE-2025-59237 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20262+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-11622 Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges. Endpoint Manager 2024+ Fix from $1,9502025-10-13 MEDIUM 6.5 CVE-2025-61505 e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previo… E107 after 2.3.3 Fix from $1,6002025-10-10 CRITICAL 9.8 CVE-2025-35050 Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to ex… Project Center Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-35051 Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthentica… Project Center Mitigation only Fix from $2,3002025-10-09 MEDIUM 6.5 CVE-2025-60834 A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input. Uzy Ssm Mall No fix yet Fix from $1,6002025-10-08 MEDIUM 6.5 CVE-2025-60828 WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface. Wukong Crm No fix yet Fix from $1,6002025-10-08 MEDIUM 6.5 CVE-2025-60830 redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key. Redragon Erp No fix yet Fix from $1,6002025-10-08 CRITICAL 9.8 CVE-2025-11346 A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such ma… Ilias Mitigation only Fix from $2,3002025-10-06 CRITICAL 9.8 CVE-2025-11345 A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulati… Ilias Mitigation only Fix from $2,3002025-10-06 CRITICAL 10.0 CVE-2025-10363 Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affe… Mitigation only Fix from $2,3002025-10-06