Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-31103
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server whe…
A Blog Cms
2.10.58 / 2.11.70+
CRITICAL 9.8
CVE-2025-22526
Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performancestats allows Object Injectio…
Mitigation only
HIGH 8.8
CVE-2025-2485
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…
Drag And Drop Multiple File Upload Contact Form 7
1.3.8.9+
CRITICAL 9.0
CVE-2025-26873
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
Mitigation only
HIGH 7.2
CVE-2025-2855
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of…
Eladmin
after 2.7
HIGH 7.2
CVE-2025-30773
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects T…
Mitigation only
CRITICAL 9.8
CVE-2025-2332
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…
Mitigation only
HIGH 7.2
CVE-2025-1913
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all version…
Product Import Export For Woocommerce
2.5.1+
HIGH 7.2
CVE-2024-13889
The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of …
Mitigation only
CRITICAL 9.8
CVE-2025-29310
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows …
Onos
Mitigation only
CRITICAL 9.8
CVE-2025-2690
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src…
Yii
after 2.0.39
CRITICAL 9.8
CVE-2025-2689
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of…
Yii
after 2.0.45
HIGH 8.8
CVE-2025-2622
A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/w…
Snail Job
No fix yet
HIGH 7.2
CVE-2025-1971
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via …
Import Export Wordpress Users
2.6.3+
HIGH 8.8
CVE-2025-0724
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…
Profilegrid
5.9.4.6+
HIGH 8.8
CVE-2025-29807
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Dataverse
Mitigation only
HIGH 7.5
CVE-2025-30160
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (…
Redlib
0.36.0+
HIGH 8.8
CVE-2025-23120EPSS 22%
A vulnerability allowing remote code execution (RCE) for domain users.
Veeam Backup \& Replication
12.3.1.1139+
HIGH 7.2
CVE-2024-13921
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.…
Order Export \& Order Import For Woocommerce
2.6.1+
CRITICAL 9.8
CVE-2024-9701
A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacke…
Patch available
CRITICAL 9.8
CVE-2024-9053
vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop…
Vllm
No fix yet
CRITICAL 9.8
CVE-2024-9070
A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attac…
Mitigation only
CRITICAL 9.8
CVE-2024-8502
A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of u…
Mitigation only
CRITICAL 9.8
CVE-2024-12433
A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey…
Ragflow
0.14.0+
CRITICAL 9.8
CVE-2024-12029EPSS 6%
A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability…
Patch available
CRITICAL 9.8
CVE-2024-12044
A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` fu…
Mitigation only
HIGH 8.8
CVE-2024-11039
A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and …
Gpt Academic
3.91+
CRITICAL 9.8
CVE-2024-11041
vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse receive…
Vllm
No fix yet
CRITICAL 9.8
CVE-2024-10553
A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization o…
H2o
Patch available
CRITICAL 9.8
CVE-2024-10190
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling o…
Horovod
after 0.28.1