Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-6742
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ…
Sureforms
0.0.14 / 1.0.7+
HIGH 7.3
CVE-2025-7216
A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /app…
Mitigation only
CRITICAL 9.8
CVE-2025-49533EPSS 52%
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbi…
Experience Manager
after 6.5.23.0
CRITICAL 9.6
CVE-2025-27203
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution…
Connect Desktop Application
2025.5.5+
HIGH 8.6
CVE-2025-47994
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
365 Apps
Mitigation only
CRITICAL 9.1
CVE-2025-42980
SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when d…
Mitigation only
CRITICAL 9.1
CVE-2025-42963
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java obj…
Mitigation only
CRITICAL 9.1
CVE-2025-42964
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize…
Mitigation only
CRITICAL 9.1
CVE-2025-42966
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization …
Mitigation only
CRITICAL 9.8
CVE-2025-6810
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…
Activereports.net
Mitigation only
CRITICAL 9.8
CVE-2025-6811
Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remo…
Activereports.net
Mitigation only
MEDIUM 5.9
CVE-2025-7099
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality …
Boyuncms
after 1.21
HIGH 8.8
CVE-2025-52828
Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <…
Mitigation only
CRITICAL 9.8
CVE-2025-49417
Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiaction allows Object Injection.T…
Mitigation only
MEDIUM 6.5
CVE-2025-43713
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support …
Mitigation only
CRITICAL 10.0
CVE-2025-34067EPSS 20%
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform du…
Mitigation only
CRITICAL 9.8
CVE-2024-13786
The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted…
Mitigation only
HIGH 8.8
CVE-2025-6464
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
Forminator
1.44.3+
CRITICAL 10.0
CVE-2025-34060
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the …
Mitigation only
HIGH 7.8
CVE-2025-53416
Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution
Mitigation only
HIGH 7.8
CVE-2025-53415
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution
Mitigation only
MEDIUM 6.0
CVE-2025-53393
In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.
Patch available
CRITICAL 9.8
CVE-2025-32897
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This security vulnerability is the same as CVE-2024-47552, but the ver…
Seata
2.3.0+
HIGH 8.8
CVE-2025-52826
Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3.
Mitigation only
HIGH 8.8
CVE-2025-52827
Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3.
Mitigation only
CRITICAL 9.8
CVE-2025-52724
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects Amwerk: from n/a through <= 1.…
Mitigation only
CRITICAL 9.8
CVE-2025-52725
Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <…
Mitigation only
CRITICAL 9.8
CVE-2025-28970
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects …
Mitigation only
CRITICAL 9.8
CVE-2025-53002
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and…
Llama Factory
0.9.4+
CRITICAL 9.8
CVE-2025-36038EPSS 9%
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence …
Websphere Application Server
8.5.5.28 / 9.0.5.25+