Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-14974
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14512
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-66713
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Foundation Apache Axis2/Java through 2.0.0…
Axis2\/java
2.0.1+
CRITICAL 10.0
CVE-2026-11756
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Re…
No fix yet
HIGH 8.8
CVE-2026-65617
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availabi…
Artifactory
7.111.18 / 7.117.25+
CRITICAL 9.8
CVE-2026-63077 KEVEPSS 11%
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Teamcity
2025.11.7 / 2026.1.3+
HIGH 8.8
CVE-2026-15962
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deseriali…
No fix yet
CRITICAL 9.9
CVE-2026-50517
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
365 Copilot
No fix yet
HIGH 8.7
CVE-2026-21655
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Applic…
No fix yet
HIGH 7.2
CVE-2026-65497
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
No fix yet
HIGH 7.5
CVE-2026-65493
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
No fix yet
CRITICAL 9.8
CVE-2026-59544
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
No fix yet
CRITICAL 9.0
CVE-2026-16723
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul…
No fix yet
CRITICAL 9.9
CVE-2026-60369
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
No fix yet
CRITICAL 9.8
CVE-2026-60372
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
No fix yet
HIGH 8.8
CVE-2026-60373
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
No fix yet
HIGH 8.8
CVE-2026-60439
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
Mitigation only
HIGH 8.8
CVE-2026-61246
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
No fix yet
CRITICAL 10.0
CVE-2026-60366
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
No fix yet
CRITICAL 9.8
CVE-2026-60367
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…
Platform Security For Java
No fix yet
HIGH 8.1
CVE-2026-13185
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize…
Telerik Ui For Asp.net Ajax
2026.2.708+
HIGH 8.1
CVE-2026-13190
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation…
Telerik Ui For Asp.net Ajax
2026.2.708+
HIGH 7.4
CVE-2026-47058
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Dif…
Jre
No fix yet
CRITICAL 9.8
CVE-2026-64606
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…
Fory
1.4.0+
CRITICAL 9.8
CVE-2026-64608
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…
Fory
1.4.0+
CRITICAL 9.8
CVE-2026-63767
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers t…
No fix yet
CRITICAL 9.1
CVE-2026-28220
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distribu…
Wazuh
4.14.5+
HIGH 7.8
CVE-2026-12484
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras…
No fix yet
CRITICAL 9.9
CVE-2026-8476
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache …
Langflow
1.10.1+
HIGH 8.0
CVE-2026-45162
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize…
No fix yet