Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 6.4 CVE-2025-61765 python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio vers… Patch available Fix from $1,6002025-10-06 CRITICAL 9.8 CVE-2023-49886 IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa… Transformation Extender Advanced Mitigation only Fix from $2,3002025-10-06 MEDIUM 6.3 CVE-2025-11273 A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oa… Mitigation only Fix from $1,6002025-10-04 CRITICAL 9.8 CVE-2025-61622EPSS 41% Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows… Fory after 0.12.2 Fix from $2,3002025-10-01 HIGH 7.3 CVE-2025-11135 A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the func… Mitigation only Fix from $1,9502025-09-29 CRITICAL 10.0 CVE-2025-58384 In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the W… Mitigation only Fix from $2,3002025-09-26 MEDIUM 6.3 CVE-2025-10975 A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.rob… Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.3 CVE-2025-10974 A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of th… Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.3 CVE-2025-10965 A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/co… Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.3 CVE-2025-10950 A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file m… Mitigation only Fix from $1,6002025-09-25 HIGH 8.8 CVE-2025-56816 Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML … Datart No fix yet Fix from $1,9502025-09-24 MEDIUM 5.3 CVE-2025-48459 Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to… Iotdb 2.0.5+ Fix from $1,6002025-09-24 CRITICAL 9.8 CVE-2025-26399 KEVEPSS 88% SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp… Web Help Desk after 12.8.6 Fix from $2,3002025-09-23 HIGH 7.2 CVE-2025-58662 Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome … Mitigation only Fix from $1,9502025-09-22 HIGH 7.2 CVE-2025-57919 Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.This issue affects ConveyThis: … Mitigation only Fix from $1,9502025-09-22 HIGH 7.2 CVE-2025-53465 Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This issue affects GSheets Connect… Mitigation only Fix from $1,9502025-09-22 CRITICAL 9.8 CVE-2025-10771 A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnectio… Jimureport after 2.1.2 Fix from $2,3002025-09-21 MEDIUM 6.5 CVE-2025-10770 A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of… Jimureport after 2.1.2 Fix from $1,6002025-09-21 CRITICAL 9.8 CVE-2025-10768 A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB… H2o after 3.46.0.8 Fix from $2,3002025-09-21 CRITICAL 9.8 CVE-2025-10769 A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC… H2o after 3.46.0.8 Fix from $2,3002025-09-21 CRITICAL 9.8 CVE-2025-6544 A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary c… H2o after 3.46.0.8 Fix from $2,3002025-09-21 HIGH 7.3 CVE-2025-9906 The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted… Keras 3.11.0+ Fix from $1,9502025-09-19 HIGH 8.1 CVE-2025-59713 Snipe-IT before 8.1.18 allows unsafe deserialization. Snipe It 8.1.18+ Fix from $1,9502025-09-19 CRITICAL 9.8 CVE-2025-10035 KEVEPSS 100% A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to… Goanywhere Managed File Transfer 7.6.3 / 7.8.4+ Fix from $2,3002025-09-18 CRITICAL 9.8 CVE-2025-9083 The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object… Ninja Forms 3.11.1+ Fix from $2,3002025-09-18 HIGH 7.8 CVE-2025-59050 Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled data received in a WM_COPYDATA… Greenshot 1.3.301+ Fix from $1,9502025-09-16 CRITICAL 9.8 CVE-2025-10492 A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to … Jasperreports Io after 9.0.2 Fix from $2,3002025-09-16 MEDIUM 6.5 CVE-2025-59328 A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr… Fory 0.12.2+ Fix from $1,6002025-09-15 CRITICAL 9.8 CVE-2025-58748 Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) … Dataease 2.10.13+ Fix from $2,3002025-09-15 CRITICAL 9.8 CVE-2025-58046 Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to… Dataease 2.10.13+ Fix from $2,3002025-09-15