Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2024-47552 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.… Seata 2.2.0+ Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2025-27781 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inferenc… Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 CRITICAL 9.8 CVE-2025-27778 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remo… Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 CRITICAL 9.8 CVE-2025-27779 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `m… Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 CRITICAL 9.8 CVE-2025-27780 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in … Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 CRITICAL 9.0 CVE-2025-29783 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization… Vllm 0.8.0+ Fix from $2,3002025-03-19 CRITICAL 9.8 CVE-2024-13410 The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versio… Mitigation only Fix from $2,3002025-03-19 HIGH 7.3 CVE-2025-2376 A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCo… Mitigation only Fix from $1,9502025-03-17 HIGH 8.8 CVE-2025-26921 Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object… Mitigation only Fix from $1,9502025-03-15 CRITICAL 9.8 CVE-2025-2000 A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma… Qiskit 1.4.2+ Fix from $2,3002025-03-14 CRITICAL 9.8 CVE-2024-13824 The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 … Ciyashop 4.19.1+ Fix from $2,3002025-03-14 HIGH 7.5 CVE-2024-10942 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via dese… Mitigation only Fix from $1,9502025-03-13 CRITICAL 9.8 CVE-2025-27925 Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. Automation 5.8+ Fix from $2,3002025-03-10 CRITICAL 9.8 CVE-2025-24813 KEVEPSS 100% Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade… Tomcat 9.0.99 / 10.1.35+ Fix from $2,3002025-03-10 CRITICAL 9.8 CVE-2025-25940 VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java. Visicut No fix yet Fix from $2,3002025-03-10 CRITICAL 9.8 CVE-2025-27816 A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deseria… Mitigation only Fix from $2,3002025-03-07 HIGH 7.2 CVE-2024-13906 The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all v… Mitigation only Fix from $1,9502025-03-07 HIGH 7.2 CVE-2025-2043 A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#theme… Pb Cms Mitigation only Fix from $1,9502025-03-06 HIGH 7.8 CVE-2024-12742EPSS 6% A deserialization of untrusted data vulnerability exists in NI G Web Development Software that may result in arbitrary code execution.  Successful ex… Mitigation only Fix from $1,9502025-03-06 HIGH 8.1 CVE-2025-0956 The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via de… Mitigation only Fix from $1,9502025-03-05 CRITICAL 9.8 CVE-2024-13787 The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deser… Mitigation only Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2024-13777 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… Zoomsounds after 6.91 Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-0912 The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of u… Givewp 3.20.0+ Fix from $2,3002025-03-04 HIGH 8.8 CVE-2025-26999 Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.Th… Mitigation only Fix from $1,9502025-03-03 HIGH 7.2 CVE-2025-26885 Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress … Mitigation only Fix from $1,9502025-03-03 HIGH 8.8 CVE-2025-26967 Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issu… Events Calendar* 2.3.15+ Fix from $1,9502025-03-03 CRITICAL 9.8 CVE-2024-47092 Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1 Check Mk Python Api 5.8.1+ Fix from $2,3002025-03-03 HIGH 7.2 CVE-2024-13833 The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via dese… Mitigation only Fix from $1,9502025-03-01 MEDIUM 6.3 CVE-2025-0769 PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize… Mitigation only Fix from $1,6002025-02-28 HIGH 7.2 CVE-2024-13831 The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization o… Tabs For Woocommerce Mitigation only Fix from $1,9502025-02-28