Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-7876 A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of th… Metacrm after 6.4.2 Fix from $2,3002025-07-20 CRITICAL 9.8 CVE-2025-53770 KEVEPSS 100% Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsof… Sharepoint Server 16.0.18526.20508+ Fix from $2,3002025-07-20 CRITICAL 9.8 CVE-2025-7696 The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all v… Mitigation only Fix from $2,3002025-07-19 CRITICAL 9.8 CVE-2025-7697 The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in a… Mitigation only Fix from $2,3002025-07-19 HIGH 8.8 CVE-2025-7433 A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code ex… Mitigation only Fix from $1,9502025-07-17 HIGH 8.8 CVE-2025-31422 Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme visual-arts allows Object Injection.This issue a… Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.8 CVE-2025-30973 Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This issue affects CoSchool LMS: from… Mitigation only Fix from $2,3002025-07-16 CRITICAL 9.8 CVE-2025-28961 Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Short… Mitigation only Fix from $2,3002025-07-16 CRITICAL 9.8 CVE-2025-30949 Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects S… Mitigation only Fix from $2,3002025-07-16 HIGH 8.8 CVE-2025-24777 Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7. Mitigation only Fix from $1,9502025-07-16 HIGH 8.8 CVE-2025-24779 Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: from n/a through < 2.9.3. Mitigation only Fix from $1,9502025-07-16 HIGH 7.2 CVE-2025-53990 Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilde… Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.8 CVE-2025-49837 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49838 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49839 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49840 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-49841 GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability i… Gpt Sovits Webui after 20250228v3 Fix from $2,3002025-07-15 MEDIUM 5.9 CVE-2025-30761 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are… Jre Mitigation only Fix from $1,6002025-07-15 HIGH 8.8 CVE-2025-7504 The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars para… Friends 3.5.2+ Fix from $1,9502025-07-12 CRITICAL 9.0 CVE-2025-30023 The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution atta… Camera Station 5.32.137 / 5.58.47195+ Fix from $2,3002025-07-11 HIGH 7.8 CVE-2025-30025 The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation. Camera Station Pro 5.32.137 / 6.8.43213+ Fix from $1,9502025-07-11 HIGH 7.5 CVE-2025-6742 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ… Sureforms 0.0.14 / 1.0.7+ Fix from $1,9502025-07-09 HIGH 7.3 CVE-2025-7216 A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /app… Mitigation only Fix from $1,9502025-07-09 CRITICAL 9.8 CVE-2025-49533EPSS 52% Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbi… Experience Manager after 6.5.23.0 Fix from $2,3002025-07-08 CRITICAL 9.6 CVE-2025-27203 Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution… Connect Desktop Application 2025.5.5+ Fix from $2,3002025-07-08 HIGH 8.6 CVE-2025-47994 Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 CRITICAL 9.1 CVE-2025-42980 SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when d… Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.1 CVE-2025-42963 A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java obj… Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.1 CVE-2025-42964 SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize… Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.1 CVE-2025-42966 SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization … Mitigation only Fix from $2,3002025-07-08