Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 6.3 CVE-2025-10433 A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the file /admin/api/workspace/def… Mitigation only Fix from $1,6002025-09-15 HIGH 7.3 CVE-2025-10164 A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tenso… Mitigation only Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-55232 Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. Hpc Pack 6.3.8352+ Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-54897EPSS 19% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20100+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-53303 Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core:… Mitigation only Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-48101 Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant … Mitigation only Fix from $1,9502025-09-09 HIGH 8.1 CVE-2025-47579 Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/… Photography after 7.7.2 Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-41701 An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affec… Mitigation only Fix from $1,9502025-09-09 CRITICAL 10.0 CVE-2025-42944 Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting… Mitigation only Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-58756 MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full… Medical Open Network For Ai after 1.5.0 Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-58757 MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function… Medical Open Network For Ai after 1.5.0 Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-58782 Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Co… Jackrabbit 2.22.2+ Fix from $1,6002025-09-08 HIGH 7.2 CVE-2025-58839 Deserialization of Untrusted Data vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Object Injection.This issue … Mitigation only Fix from $1,9502025-09-05 HIGH 7.2 CVE-2025-58815 Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon aitasi-coming-soon allows Object Injection.This issue affects Aitasi… Mitigation only Fix from $1,9502025-09-05 HIGH 7.8 CVE-2025-48535 In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywh… Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-32312 In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next… Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-9365 Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow … Mitigation only Fix from $1,9502025-09-03 CRITICAL 9.0 CVE-2025-53690 KEVEPSS 31% Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss… Experience Commerce after 9.0 Fix from $2,3002025-09-03 HIGH 7.2 CVE-2025-58643 Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-quotes-daylight-edition allows… Mitigation only Fix from $1,9502025-09-03 HIGH 7.2 CVE-2025-58644 Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes-tql-edition allows Object In… Mitigation only Fix from $1,9502025-09-03 HIGH 7.2 CVE-2025-58642 Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight-quotes-day-ross-edition allo… Mitigation only Fix from $1,9502025-09-03 HIGH 8.8 CVE-2025-53691 Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (… Experience Commerce 10.4+ Fix from $1,9502025-09-03 HIGH 8.8 CVE-2025-58163 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untruste… Freescout 1.8.186+ Fix from $1,9502025-09-03 MEDIUM 6.5 CVE-2025-9260 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection… Mitigation only Fix from $1,6002025-09-03 HIGH 7.8 CVE-2025-7976 Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers … Shockline 2025.4.2+ Fix from $1,9502025-09-02 HIGH 7.8 CVE-2025-9188 There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successf… Dasylab Mitigation only Fix from $1,9502025-09-02 CRITICAL 9.8 CVE-2025-5662 A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability a… Patch available Fix from $2,3002025-09-02 CRITICAL 9.8 CVE-2024-28988EPSS 39% SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… Web Help Desk after 12.8.2 Fix from $2,3002025-09-01 CRITICAL 9.8 CVE-2025-6507EPSS 14% A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code ex… Patch available Fix from $2,3002025-09-01 HIGH 8.8 CVE-2025-54742 Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro… Mitigation only Fix from $1,9502025-08-28