Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-7384
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…
Mitigation only
HIGH 8.8
CVE-2025-53772EPSS 22%
Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
Web Deploy 4.0
10.0.2001+
HIGH 8.8
CVE-2025-49712EPSS 18%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
HIGH 7.2
CVE-2025-55010
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in t…
Kanboard
1.2.47+
HIGH 7.8
CVE-2025-40759
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (Al…
Mitigation only
HIGH 8.2
CVE-2024-54678
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions <…
Mitigation only
CRITICAL 9.8
CVE-2025-45146
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnera…
Modelcache
after 0.2.0
HIGH 7.8
CVE-2025-8747
A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code…
Keras
after 3.10.0
CRITICAL 9.8
CVE-2025-53606
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): 2.4.0.
Users are recomm…
Seata
Mitigation only
HIGH 7.5
CVE-2025-8708
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeMan…
White Jotter
No fix yet
HIGH 8.4
CVE-2025-54886
skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not…
Patch available
MEDIUM 5.7
CVE-2025-55136
ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.
Patch available
MEDIUM 5.5
CVE-2025-54640
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of this vulnerability may cause playback control screen di…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2025-54639
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of this vulnerability may cause playback control screen di…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2025-54638
Issue of inconsistent read/write serialization in the ad module.
Impact: Successful exploitation of this vulnerability may affect the availability of…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2025-54620
Deserialization vulnerability of untrusted data in the ability module.
Impact: Successful exploitation of this vulnerability may affect availability.
Harmonyos
No fix yet
CRITICAL 9.8
CVE-2025-50460
A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.loa…
Mitigation only
CRITICAL 9.8
CVE-2025-50472
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model…
Mitigation only
HIGH 7.2
CVE-2025-49083
CVE-2025-49083 is a vulnerability in the management console
of Absolute Secure Access after version 12.00 and prior to version 13.56.
Attackers with …
Secure Access
13.56+
MEDIUM 6.5
CVE-2025-25691
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO…
Prestashop
No fix yet
MEDIUM 6.5
CVE-2025-25692
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r…
Prestashop
No fix yet
CRITICAL 9.8
CVE-2025-53078
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
Data Management Server Firmware
2.3.13.1 / 2.6.14.1+
MEDIUM 6.3
CVE-2025-8266
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArti…
Chancms
3.1.3+
CRITICAL 9.8
CVE-2025-8227
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functio…
Chancms
3.1.3+
HIGH 8.8
CVE-2025-54366
FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a …
Freescout
1.8.86+
HIGH 7.8
CVE-2025-26397
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l…
Observability Self Hosted
2025.2.1+
MEDIUM 6.5
CVE-2025-4393
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by cr…
Mitigation only
CRITICAL 9.3
CVE-2016-15044
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the k…
No fix yet
MEDIUM 5.2
CVE-2025-43489
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize…
Poly Clariti Manager
10.12.2+
CRITICAL 9.8
CVE-2025-7916
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitr…
Mitigation only