Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2023-35814 DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. Devexpress 21.2.12+ Fix from $2,3002025-04-28 CRITICAL 9.8 CVE-2023-35815 DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. Devexpress 21.2.12+ Fix from $2,3002025-04-28 HIGH 8.1 CVE-2025-2105 The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of unt… Jupiter X Core 4.8.12+ Fix from $1,9502025-04-26 HIGH 7.2 CVE-2025-3935 KEV ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preser… Screenconnect 25.2.4+ Fix from $1,9502025-04-25 HIGH 7.2 CVE-2025-46481 Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This is… Mitigation only Fix from $1,9502025-04-24 HIGH 7.2 CVE-2025-46473 Deserialization of Untrusted Data vulnerability in Prisna Social Counter social-counter allows Object Injection.This issue affects Social Counter: fr… Mitigation only Fix from $1,9502025-04-24 CRITICAL 9.8 CVE-2025-23249 NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful ex… Nemo 25.02+ Fix from $2,3002025-04-22 HIGH 7.5 CVE-2025-3857 When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from … Mitigation only Fix from $1,9502025-04-21 CRITICAL 9.8 CVE-2025-32434 PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd sys… Pytorch 2.6.0+ Fix from $2,3002025-04-18 CRITICAL 9.8 CVE-2025-29953 Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor… Activemq Nms Openwire 2.1.1+ Fix from $2,3002025-04-18 CRITICAL 9.8 CVE-2025-39588 Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Object Injection.This issue… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-39550 Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Injection.This issue affects Fluent… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-39551 Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injection.This issue affects FluentBo… Mitigation only Fix from $2,3002025-04-17 HIGH 8.8 CVE-2025-39527 Deserialization of Untrusted Data vulnerability in bestweblayout Rating by BestWebSoft rating-bws allows Object Injection.This issue affects Rating b… Mitigation only Fix from $1,9502025-04-17 HIGH 8.8 CVE-2025-32686 Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue affects Team Members: from n/a t… Mitigation only Fix from $1,9502025-04-17 CRITICAL 9.8 CVE-2025-32658 Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects HelpGent: from n/a through <= 2… Mitigation only Fix from $2,3002025-04-17 HIGH 8.8 CVE-2025-32662 Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <… Mitigation only Fix from $1,9502025-04-17 HIGH 8.8 CVE-2025-32647 Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.This issue affects Question An… Mitigation only Fix from $1,9502025-04-17 HIGH 8.8 CVE-2025-32571 Deserialization of Untrusted Data vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Object Injection.This issue affects T… Mitigation only Fix from $1,9502025-04-17 CRITICAL 9.8 CVE-2025-32572 Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue affects Kata Plus: from n/a t… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-27286 Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injection.This issue affects Saoshya… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-27287 Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS Quiz: from n/a through <= 2.0… Mitigation only Fix from $2,3002025-04-17 HIGH 7.2 CVE-2025-39565 Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue aff… Melapress Login Security 2.1.1+ Fix from $1,9502025-04-16 MEDIUM 5.3 CVE-2025-3677 A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low… Mitigation only Fix from $1,6002025-04-16 CRITICAL 9.8 CVE-2025-30985 Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a thr… Mitigation only Fix from $2,3002025-04-15 MEDIUM 5.5 CVE-2025-3622 A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file … Mitigation only Fix from $1,6002025-04-15 MEDIUM 6.3 CVE-2025-3590 A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality.… Mitigation only Fix from $1,6002025-04-14 MEDIUM 6.2 CVE-2025-31935 Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API ma… Mitigation only Fix from $1,6002025-04-11 CRITICAL 9.8 CVE-2025-3439 The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Inje… Everest Forms 3.1.2+ Fix from $2,3002025-04-11 HIGH 8.8 CVE-2025-31932 Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Man… Mitigation only Fix from $1,9502025-04-11