Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-14974 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14512 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-66713 Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0… Axis2\/java 2.0.1+ Fix from $2,3002026-07-28 CRITICAL 10.0 CVE-2026-11756 A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Re… No fix yet Fix from $2,3002026-07-28 HIGH 8.8 CVE-2026-65617 A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availabi… Artifactory 7.111.18 / 7.117.25+ Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2026-63077 KEVEPSS 11% In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol Teamcity 2025.11.7 / 2026.1.3+ Fix from $2,3002026-07-27 HIGH 8.8 CVE-2026-15962 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deseriali… No fix yet Fix from $1,9502026-07-26 CRITICAL 9.9 CVE-2026-50517 Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. 365 Copilot No fix yet Fix from $2,3002026-07-24 HIGH 8.7 CVE-2026-21655 Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Applic… No fix yet Fix from $1,9502026-07-23 HIGH 7.2 CVE-2026-65497 Administrator PHP Object Injection in Complianz <= 7.5.0 versions. No fix yet Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-65493 Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-59544 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.0 CVE-2026-16723 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.9 CVE-2026-60369 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-60372 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 8.8 CVE-2026-60373 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60439 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java Mitigation only Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-61246 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 CRITICAL 10.0 CVE-2026-60366 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-60367 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 8.1 CVE-2026-13185 In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize… Telerik Ui For Asp.net Ajax 2026.2.708+ Fix from $1,9502026-07-22 HIGH 8.1 CVE-2026-13190 In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation… Telerik Ui For Asp.net Ajax 2026.2.708+ Fix from $1,9502026-07-22 HIGH 7.4 CVE-2026-47058 Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Dif… Jre No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-64606 Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb… Fory 1.4.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-64608 Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa… Fory 1.4.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-63767 ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers t… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.1 CVE-2026-28220 Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distribu… Wazuh 4.14.5+ Fix from $2,3002026-07-20 HIGH 7.8 CVE-2026-12484 A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras… No fix yet Fix from $1,9502026-07-19 CRITICAL 9.9 CVE-2026-8476 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache … Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 8.0 CVE-2026-45162 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize… No fix yet Fix from $1,9502026-07-17