Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.5 CVE-2025-6742 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ… Sureforms 0.0.14 / 1.0.7+ Fix from $1,9502025-07-09 HIGH 7.3 CVE-2025-7216 A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /app… Mitigation only Fix from $1,9502025-07-09 CRITICAL 9.8 CVE-2025-49533EPSS 52% Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbi… Experience Manager after 6.5.23.0 Fix from $2,3002025-07-08 CRITICAL 9.6 CVE-2025-27203 Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution… Connect Desktop Application 2025.5.5+ Fix from $2,3002025-07-08 HIGH 8.6 CVE-2025-47994 Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 CRITICAL 9.1 CVE-2025-42980 SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when d… Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.1 CVE-2025-42963 A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java obj… Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.1 CVE-2025-42964 SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize… Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.1 CVE-2025-42966 SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization … Mitigation only Fix from $2,3002025-07-08 CRITICAL 9.8 CVE-2025-6810 Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers… Activereports.net Mitigation only Fix from $2,3002025-07-07 CRITICAL 9.8 CVE-2025-6811 Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remo… Activereports.net Mitigation only Fix from $2,3002025-07-07 MEDIUM 5.9 CVE-2025-7099 A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality … Boyuncms after 1.21 Fix from $1,6002025-07-07 HIGH 8.8 CVE-2025-52828 Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <… Mitigation only Fix from $1,9502025-07-04 CRITICAL 9.8 CVE-2025-49417 Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiaction allows Object Injection.T… Mitigation only Fix from $2,3002025-07-04 MEDIUM 6.5 CVE-2025-43713 ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support … Mitigation only Fix from $1,6002025-07-03 CRITICAL 10.0 CVE-2025-34067EPSS 20% An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform du… Mitigation only Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2024-13786 The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted… Mitigation only Fix from $2,3002025-07-02 HIGH 8.8 CVE-2025-6464 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up… Forminator 1.44.3+ Fix from $1,9502025-07-02 CRITICAL 10.0 CVE-2025-34060 A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the … Mitigation only Fix from $2,3002025-07-01 HIGH 7.8 CVE-2025-53416 Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Mitigation only Fix from $1,9502025-06-30 HIGH 7.8 CVE-2025-53415 Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Mitigation only Fix from $1,9502025-06-30 MEDIUM 6.0 CVE-2025-53393 In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics. Patch available Fix from $1,6002025-06-28 CRITICAL 9.8 CVE-2025-32897 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver… Seata 2.3.0+ Fix from $2,3002025-06-28 HIGH 8.8 CVE-2025-52826 Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3. Mitigation only Fix from $1,9502025-06-27 HIGH 8.8 CVE-2025-52827 Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3. Mitigation only Fix from $1,9502025-06-27 CRITICAL 9.8 CVE-2025-52724 Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects Amwerk: from n/a through <= 1.… Mitigation only Fix from $2,3002025-06-27 CRITICAL 9.8 CVE-2025-52725 Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <… Mitigation only Fix from $2,3002025-06-27 CRITICAL 9.8 CVE-2025-28970 Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects … Mitigation only Fix from $2,3002025-06-27 CRITICAL 9.8 CVE-2025-53002 LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and… Llama Factory 0.9.4+ Fix from $2,3002025-06-26 CRITICAL 9.8 CVE-2025-36038EPSS 9% IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence … Websphere Application Server 8.5.5.28 / 9.0.5.25+ Fix from $2,3002025-06-25