Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-7384 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… Mitigation only Fix from $2,3002025-08-13 HIGH 8.8 CVE-2025-53772EPSS 22% Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. Web Deploy 4.0 10.0.2001+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-49712EPSS 18% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server Mitigation only Fix from $1,9502025-08-12 HIGH 7.2 CVE-2025-55010 Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in t… Kanboard 1.2.47+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-40759 A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (Al… Mitigation only Fix from $1,9502025-08-12 HIGH 8.2 CVE-2024-54678 A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions <… Mitigation only Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-45146 ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnera… Modelcache after 0.2.0 Fix from $2,3002025-08-11 HIGH 7.8 CVE-2025-8747 A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code… Keras after 3.10.0 Fix from $1,9502025-08-11 CRITICAL 9.8 CVE-2025-53606 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm… Seata Mitigation only Fix from $2,3002025-08-08 HIGH 7.5 CVE-2025-8708 A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeMan… White Jotter No fix yet Fix from $1,9502025-08-08 HIGH 8.4 CVE-2025-54886 skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not… Patch available Fix from $1,9502025-08-08 MEDIUM 5.7 CVE-2025-55136 ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used. Patch available Fix from $1,6002025-08-07 MEDIUM 5.5 CVE-2025-54640 ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen di… Harmonyos No fix yet Fix from $1,6002025-08-06 MEDIUM 5.5 CVE-2025-54639 ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen di… Harmonyos No fix yet Fix from $1,6002025-08-06 MEDIUM 5.5 CVE-2025-54638 Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of… Harmonyos No fix yet Fix from $1,6002025-08-06 MEDIUM 5.5 CVE-2025-54620 Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002025-08-06 CRITICAL 9.8 CVE-2025-50460 A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.loa… Mitigation only Fix from $2,3002025-08-01 CRITICAL 9.8 CVE-2025-50472 The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model… Mitigation only Fix from $2,3002025-08-01 HIGH 7.2 CVE-2025-49083 CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with … Secure Access 13.56+ Fix from $1,9502025-07-31 MEDIUM 6.5 CVE-2025-25691 A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO… Prestashop No fix yet Fix from $1,6002025-07-30 MEDIUM 6.5 CVE-2025-25692 A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r… Prestashop No fix yet Fix from $1,6002025-07-30 CRITICAL 9.8 CVE-2025-53078 Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system Data Management Server Firmware 2.3.13.1 / 2.6.14.1+ Fix from $2,3002025-07-29 MEDIUM 6.3 CVE-2025-8266 A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArti… Chancms 3.1.3+ Fix from $1,6002025-07-28 CRITICAL 9.8 CVE-2025-8227 A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functio… Chancms 3.1.3+ Fix from $2,3002025-07-27 HIGH 8.8 CVE-2025-54366 FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a … Freescout 1.8.86+ Fix from $1,9502025-07-26 HIGH 7.8 CVE-2025-26397 SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l… Observability Self Hosted 2025.2.1+ Fix from $1,9502025-07-24 MEDIUM 6.5 CVE-2025-4393 Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by cr… Mitigation only Fix from $1,6002025-07-24 CRITICAL 9.3 CVE-2016-15044 A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the k… No fix yet Fix from $2,3002025-07-23 MEDIUM 5.2 CVE-2025-43489 A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize… Poly Clariti Manager 10.12.2+ Fix from $1,6002025-07-23 CRITICAL 9.8 CVE-2025-7916 WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitr… Mitigation only Fix from $2,3002025-07-21