Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2025-2566
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially craft…
Mitigation only
CRITICAL 9.3
CVE-2025-25034
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of…
No fix yet
HIGH 8.1
CVE-2025-47771
PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in…
Patch available
HIGH 8.0
CVE-2025-6279
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the f…
Upsonic
after 0.55.6
CRITICAL 9.8
CVE-2025-49213EPSS 10%
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on…
Trend Micro Endpoint Encryption
6.0.0.4013+
HIGH 8.8
CVE-2025-49214
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution o…
Trend Micro Endpoint Encryption
6.0.0.4013+
CRITICAL 9.8
CVE-2025-49217
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on…
Trend Micro Endpoint Encryption
6.0.0.4013+
CRITICAL 9.8
CVE-2025-49212EPSS 10%
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on…
Trend Micro Endpoint Encryption
6.0.0.4013+
CRITICAL 9.8
CVE-2025-49220
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on …
Apex Central
Mitigation only
CRITICAL 9.8
CVE-2025-49219
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on…
Apex Central
Mitigation only
CRITICAL 9.8
CVE-2025-49330
Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This…
Mitigation only
HIGH 7.2
CVE-2025-49331
Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue a…
Mitigation only
CRITICAL 9.8
CVE-2025-30618
Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows Object Injection.This issue a…
Mitigation only
CRITICAL 9.8
CVE-2025-31919
Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7.
Mitigation only
HIGH 8.1
CVE-2025-24919
A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and Contro…
Mitigation only
HIGH 8.8
CVE-2025-47166EPSS 15%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Enterprise Server
16.0.18526.20396+
HIGH 8.8
CVE-2025-47163EPSS 15%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Enterprise Server
16.0.18526.20396+
CRITICAL 9.8
CVE-2025-49507
Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affects CozyStay: from n/a through …
Mitigation only
HIGH 8.8
CVE-2025-27818
A possible security vulnerability has been identified in Apache Kafka.
This requires access to a alterConfig to the cluster resource, or Kafka Connec…
Kafka
3.9.1+
HIGH 7.5
CVE-2025-27819
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…
Kafka
after 3.3.2
CRITICAL 9.8
CVE-2025-31398
Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative …
Mitigation only
CRITICAL 9.8
CVE-2025-31429
Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This is…
Mitigation only
CRITICAL 9.8
CVE-2025-31052
Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This …
Mitigation only
CRITICAL 9.8
CVE-2025-31396
Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Busine…
Mitigation only
HIGH 8.9
CVE-2025-49127
Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthentic…
Mitigation only
CRITICAL 9.8
CVE-2025-27531
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 before 2.1.0,
this issue would al…
Inlong
2.1.0+
CRITICAL 9.8
CVE-2025-49072
Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue affects Mr. Murphy: from n/a …
Mitigation only
CRITICAL 9.8
CVE-2025-49073
Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: …
Sweet Dessert
1.1.13+
HIGH 7.5
CVE-2025-47584
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.
Photography
after 7.7.2
HIGH 8.8
CVE-2025-39358
Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Pos…
Mitigation only