Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-32607 Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBo… Mitigation only Fix from $2,3002025-04-11 CRITICAL 9.8 CVE-2025-32568 Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects … Mitigation only Fix from $2,3002025-04-11 CRITICAL 9.8 CVE-2025-32569 Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from… Mitigation only Fix from $2,3002025-04-11 HIGH 8.8 CVE-2025-32143 Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a th… Mitigation only Fix from $1,9502025-04-11 HIGH 8.8 CVE-2025-32144 Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Boa… Mitigation only Fix from $1,9502025-04-11 HIGH 8.8 CVE-2025-32145 Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro… Mitigation only Fix from $1,9502025-04-10 CRITICAL 9.8 CVE-2025-32375EPSS 50% BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure dese… Bentoml 1.4.8+ Fix from $2,3002025-04-09 HIGH 8.4 CVE-2025-30285EPSS 27% ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit… Coldfusion Mitigation only Fix from $1,9502025-04-08 HIGH 8.4 CVE-2025-30284 ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit… Coldfusion Mitigation only Fix from $1,9502025-04-08 CRITICAL 9.1 CVE-2025-24447 ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit… Coldfusion Mitigation only Fix from $2,3002025-04-08 HIGH 7.2 CVE-2025-29793EPSS 22% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Enterprise Server 16.0.18526.20172+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-3413 A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this… Springboot Admin after 2017-12-26 Fix from $1,9502025-04-08 HIGH 7.3 CVE-2025-3425 The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through … Mitigation only Fix from $1,9502025-04-07 MEDIUM 6.2 CVE-2025-2251 A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. … Patch available Fix from $1,6002025-04-07 HIGH 7.5 CVE-2025-31175 Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity. Emui Mitigation only Fix from $1,9502025-04-07 MEDIUM 6.5 CVE-2025-3250 A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of t… Eladmin Mitigation only Fix from $1,6002025-04-04 CRITICAL 9.8 CVE-2025-27520EPSS 36% BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerabilit… Bentoml after 1.4.2 Fix from $2,3002025-04-04 CRITICAL 9.8 CVE-2025-2244 A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on u… Gravityzone 6.41.2-1+ Fix from $2,3002025-04-04 MEDIUM 5.3 CVE-2025-3165 A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend… Mitigation only Fix from $1,6002025-04-03 HIGH 7.8 CVE-2025-3162 A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file… Lmdeploy after 0.7.1 Fix from $1,9502025-04-03 HIGH 8.8 CVE-2025-30889 Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial … Mitigation only Fix from $1,9502025-04-03 CRITICAL 9.8 CVE-2024-39780 A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting… Robot Operating System Patch available Fix from $2,3002025-04-02 CRITICAL 9.8 CVE-2025-31612 Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll cbxpoll allows Object Injection.This issue affects CBX Poll: from n/a through… Mitigation only Fix from $2,3002025-04-01 HIGH 8.8 CVE-2025-30892 Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravel… Mitigation only Fix from $1,9502025-04-01 HIGH 8.8 CVE-2025-27130 Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrar… Welcart E Commerce after 2.11.6 Fix from $1,9502025-04-01 CRITICAL 9.8 CVE-2025-30065EPSS 41% Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco… Parquet Java 1.15.1+ Fix from $2,3002025-04-01 HIGH 8.8 CVE-2025-31074 Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This issue affects Mobile DJ Mana… Mitigation only Fix from $1,9502025-04-01 CRITICAL 9.8 CVE-2025-31084 Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affec… Sunshine Photo Cart 3.4.11+ Fix from $2,3002025-04-01 CRITICAL 9.8 CVE-2025-31087 Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-bill… Mitigation only Fix from $2,3002025-04-01 HIGH 8.8 CVE-2025-31129 Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnera… Patch available Fix from $1,9502025-03-31