Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.1 CVE-2026-14890 SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authenticatio… Sglang after 0.5.14 Fix from $2,3002026-07-16 HIGH 8.1 CVE-2026-15008 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletio… No fix yet Fix from $1,9502026-07-16 HIGH 7.8 CVE-2026-47472 NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deser… Mitigation only Fix from $1,9502026-07-14 HIGH 8.4 CVE-2026-24233 NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthentica… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.4 CVE-2026-24220 NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauth… Mitigation only Fix from $1,6002026-07-14 CRITICAL 9.8 CVE-2026-24227 NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability… Tensorrt 11.0+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-50649 Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. .net Framework 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50646 Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. .net Framework 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-55944 Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. Dynamics Nav Mitigation only Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-50509 Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.6 CVE-2026-45077 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the se… Symfony 5.4.52 / 6.4.40+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-58644 KEVEPSS 45% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-55009 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. Exchange Server 15.02.2562.045+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-54117 Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-54118 Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-50522 KEVEPSS 77% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.5 CVE-2026-50652 Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. .net Framework Mitigation only Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-12583 The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unaut… Mitigation only Fix from $1,9502026-07-14 HIGH 7.6 CVE-2026-58233 SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when proce… Mitigation only Fix from $1,9502026-07-14 HIGH 7.2 CVE-2026-59521 Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Rea… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.8 CVE-2026-59518 Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a thr… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-57770 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Pho… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-57738 Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-57744 Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Them… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-57724 Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. Mitigation only Fix from $2,3002026-07-13 HIGH 8.8 CVE-2026-57713 Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Even… Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-57371 Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a … Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.3 CVE-2026-15531 A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function… Patch available Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15535 A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.d… Patch available Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15529 A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py… Patch available Fix from $1,6002026-07-13