Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.3 CVE-2025-2566 Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially craft… Mitigation only Fix from $2,3002025-06-24 CRITICAL 9.3 CVE-2025-25034 A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of… No fix yet Fix from $2,3002025-06-20 HIGH 8.1 CVE-2025-47771 PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in… Patch available Fix from $1,9502025-06-20 HIGH 8.0 CVE-2025-6279 A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the f… Upsonic after 0.55.6 Fix from $1,9502025-06-19 CRITICAL 9.8 CVE-2025-49213EPSS 10% An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on… Trend Micro Endpoint Encryption 6.0.0.4013+ Fix from $2,3002025-06-17 HIGH 8.8 CVE-2025-49214 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution o… Trend Micro Endpoint Encryption 6.0.0.4013+ Fix from $1,9502025-06-17 CRITICAL 9.8 CVE-2025-49217 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on… Trend Micro Endpoint Encryption 6.0.0.4013+ Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-49212EPSS 10% An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on… Trend Micro Endpoint Encryption 6.0.0.4013+ Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-49220 An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on … Apex Central Mitigation only Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-49219 An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on… Apex Central Mitigation only Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-49330 Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This… Mitigation only Fix from $2,3002025-06-17 HIGH 7.2 CVE-2025-49331 Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue a… Mitigation only Fix from $1,9502025-06-17 CRITICAL 9.8 CVE-2025-30618 Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows Object Injection.This issue a… Mitigation only Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-31919 Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7. Mitigation only Fix from $2,3002025-06-17 HIGH 8.1 CVE-2025-24919 A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and Contro… Mitigation only Fix from $1,9502025-06-13 HIGH 8.8 CVE-2025-47166EPSS 15% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Enterprise Server 16.0.18526.20396+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47163EPSS 15% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Enterprise Server 16.0.18526.20396+ Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2025-49507 Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affects CozyStay: from n/a through … Mitigation only Fix from $2,3002025-06-10 HIGH 8.8 CVE-2025-27818 A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec… Kafka 3.9.1+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-27819 In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka… Kafka after 3.3.2 Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2025-31398 Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative … Mitigation only Fix from $2,3002025-06-09 CRITICAL 9.8 CVE-2025-31429 Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This is… Mitigation only Fix from $2,3002025-06-09 CRITICAL 9.8 CVE-2025-31052 Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This … Mitigation only Fix from $2,3002025-06-09 CRITICAL 9.8 CVE-2025-31396 Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Busine… Mitigation only Fix from $2,3002025-06-09 HIGH 8.9 CVE-2025-49127 Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthentic… Mitigation only Fix from $1,9502025-06-06 CRITICAL 9.8 CVE-2025-27531 Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al… Inlong 2.1.0+ Fix from $2,3002025-06-06 CRITICAL 9.8 CVE-2025-49072 Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue affects Mr. Murphy: from n/a … Mitigation only Fix from $2,3002025-06-06 CRITICAL 9.8 CVE-2025-49073 Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: … Sweet Dessert 1.1.13+ Fix from $2,3002025-06-06 HIGH 7.5 CVE-2025-47584 Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2. Photography after 7.7.2 Fix from $1,9502025-06-06 HIGH 8.8 CVE-2025-39358 Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Pos… Mitigation only Fix from $1,9502025-06-06