Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 5.3 CVE-2025-4742 A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to 9024b43f091e2eb9bac65802b120c0b35f9ba856. Affected is the functi… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-4740 A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affects unknown code of the file co… Mitigation only Fix from $1,6002025-05-16 CRITICAL 9.8 CVE-2025-47784 Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully craft… Emlog 2.5.14+ Fix from $2,3002025-05-15 MEDIUM 5.3 CVE-2025-4701 A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.l… Mitigation only Fix from $1,6002025-05-15 CRITICAL 9.5 CVE-2025-47292 Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `Debat… Patch available Fix from $2,3002025-05-14 CRITICAL 9.1 CVE-2025-3623 The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of… Uncanny Automator 6.4.0.2+ Fix from $2,3002025-05-14 HIGH 7.0 CVE-2025-30384 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Sharepoint Server 16.0.18526.20286+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-30378 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Sharepoint Server 16.0.18526.20286+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30382 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Sharepoint Server 16.0.18526.20286+ Fix from $1,9502025-05-13 CRITICAL 9.1 CVE-2025-42999 KEVEPSS 12% SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ… Netweaver Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-30012 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac… Supplier Relationship Management Mitigation only Fix from $2,3002025-05-13 MEDIUM 6.6 CVE-2025-46738 An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code. Mitigation only Fix from $1,6002025-05-12 CRITICAL 9.8 CVE-2025-47732 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. Dataverse Mitigation only Fix from $2,3002025-05-08 HIGH 7.2 CVE-2025-47683 Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Injection.This issue affects WP Mai… Mitigation only Fix from $1,9502025-05-07 HIGH 7.2 CVE-2025-47629 Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Object Injection.This issue affects WP-CRM System:… Wp Crm System after 3.4.1 Fix from $1,9502025-05-07 CRITICAL 9.8 CVE-2025-0855 The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via deserialization of untrusted … Mitigation only Fix from $2,3002025-05-06 HIGH 8.0 CVE-2025-30165 vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some mul… Vllm Mitigation only Fix from $1,9502025-05-06 CRITICAL 9.8 CVE-2025-43850 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43851 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43852 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43849 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43846 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43847 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43848 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserializ… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 HIGH 8.3 CVE-2025-4260 A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the … Youkefu No fix yet Fix from $1,9502025-05-05 HIGH 7.8 CVE-2025-46567 LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` scr… Llama Factory 1.0.0+ Fix from $1,9502025-05-01 HIGH 8.8 CVE-2025-23254 NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access … Mitigation only Fix from $1,9502025-05-01 CRITICAL 9.8 CVE-2025-32444 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM in… Vllm 0.8.5+ Fix from $2,3002025-04-30 HIGH 8.8 CVE-2025-34491 GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary cod… Mailessentials 21.8+ Fix from $1,9502025-04-28 HIGH 7.8 CVE-2025-34489 GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by… Mailessentials 21.8+ Fix from $1,9502025-04-28