Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2025-53583 Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object Injection.This issue affects Em… Mitigation only Fix from $1,9502025-08-28 HIGH 8.1 CVE-2025-53584 Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Object… Mitigation only Fix from $1,9502025-08-28 HIGH 8.1 CVE-2025-53572 Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injection.This issue affects WP Easy … Mitigation only Fix from $1,9502025-08-28 HIGH 8.1 CVE-2025-53243 Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-d… Mitigation only Fix from $1,9502025-08-28 CRITICAL 9.8 CVE-2025-52761 Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection.This issue affects WP Funnel… Mitigation only Fix from $2,3002025-08-28 CRITICAL 10.0 CVE-2024-13980 H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xh… Mitigation only Fix from $2,3002025-08-27 HIGH 7.2 CVE-2025-58218 Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition small-package-quotes-usps-edition allows Obj… Mitigation only Fix from $1,9502025-08-27 CRITICAL 9.8 CVE-2025-57773EPSS 8% DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JN… Dataease 2.10.12+ Fix from $2,3002025-08-25 HIGH 8.6 CVE-2025-43960 Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:100000… Adminer No fix yet Fix from $1,9502025-08-25 CRITICAL 9.8 CVE-2022-45134 Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly struc… Mahara 21.10.6 / 22.04.4+ Fix from $2,3002025-08-22 HIGH 8.8 CVE-2025-52287 OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability. Elite No fix yet Fix from $1,9502025-08-22 HIGH 8.7 CVE-2025-54923 CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authen… Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.6 CVE-2025-54053 Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a… Mitigation only Fix from $1,6002025-08-20 HIGH 8.8 CVE-2025-54007 Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Po… Mitigation only Fix from $1,9502025-08-20 HIGH 7.2 CVE-2025-54012 Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Co… Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.8 CVE-2025-54014 Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Object Injection.This issue affe… Mitigation only Fix from $2,3002025-08-20 HIGH 8.8 CVE-2025-53560 Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0. Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.8 CVE-2025-53299 Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This … Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-49890 Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This issue affects Organic Beauty: … Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-49434 Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue affects Cars4Rent: from n/a thr… Mitigation only Fix from $2,3002025-08-20 HIGH 8.1 CVE-2025-49438 Deserialization of Untrusted Data vulnerability in Max Chirkov Simple Login Log allows Object Injection. This issue affects Simple Login Log: from n/… Mitigation only Fix from $1,9502025-08-20 HIGH 7.5 CVE-2025-8289 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deseria… Mitigation only Fix from $1,9502025-08-20 HIGH 8.8 CVE-2025-8145 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deseria… Mitigation only Fix from $1,9502025-08-20 HIGH 7.8 CVE-2025-8875 KEV Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. N Central 2025.3.1+ Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-8963 A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDat… Jimureport after 2.1.1 Fix from $2,3002025-08-14 CRITICAL 9.8 CVE-2025-54686 Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affects Exertio: from n/a through… Mitigation only Fix from $2,3002025-08-14 HIGH 8.8 CVE-2025-49869 Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a t… Mitigation only Fix from $1,9502025-08-14 HIGH 7.2 CVE-2025-47536 Deserialization of Untrusted Data vulnerability in keywordrush Content Egg content-egg allows Object Injection.This issue affects Content Egg: from n… Mitigation only Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-23303 NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code executio… Nemo 2.3.2+ Fix from $2,3002025-08-13 CRITICAL 10.0 CVE-2025-34153 Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deser… Mitigation only Fix from $2,3002025-08-13