Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-14890
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authenticatio…
Sglang
after 0.5.14
HIGH 8.1
CVE-2026-15008
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletio…
No fix yet
HIGH 7.8
CVE-2026-47472
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deser…
Mitigation only
HIGH 8.4
CVE-2026-24233
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthentica…
Mitigation only
MEDIUM 6.4
CVE-2026-24220
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauth…
Mitigation only
CRITICAL 9.8
CVE-2026-24227
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability…
Tensorrt
11.0+
HIGH 7.8
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
.net Framework
8.0.29 / 9.0.18+
HIGH 7.8
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
.net Framework
8.0.29 / 9.0.18+
CRITICAL 9.8
CVE-2026-55944
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
Dynamics Nav
Mitigation only
HIGH 7.8
CVE-2026-50509
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.6
CVE-2026-45077
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the se…
Symfony
5.4.52 / 6.4.40+
CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
HIGH 7.8
CVE-2026-55009
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Exchange Server
15.02.2562.045+
HIGH 8.8
CVE-2026-54117
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Sql Server 2016
13.0.6500.1 / 13.0.7095.1+
HIGH 8.8
CVE-2026-54118
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Sql Server 2016
13.0.6500.1 / 13.0.7095.1+
CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
HIGH 7.5
CVE-2026-50652
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
.net Framework
Mitigation only
HIGH 8.1
CVE-2026-12583
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unaut…
Mitigation only
HIGH 7.6
CVE-2026-58233
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when proce…
Mitigation only
HIGH 7.2
CVE-2026-59521
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Rea…
Mitigation only
CRITICAL 9.8
CVE-2026-59518
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a thr…
Mitigation only
CRITICAL 9.8
CVE-2026-57770
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Pho…
Mitigation only
CRITICAL 9.8
CVE-2026-57738
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1…
Mitigation only
CRITICAL 9.8
CVE-2026-57744
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Them…
Mitigation only
CRITICAL 9.8
CVE-2026-57724
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
Mitigation only
HIGH 8.8
CVE-2026-57713
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Even…
Mitigation only
HIGH 8.8
CVE-2026-57371
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a …
Mitigation only
MEDIUM 5.3
CVE-2026-15531
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function…
Patch available
MEDIUM 6.3
CVE-2026-15535
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.d…
Patch available
MEDIUM 6.3
CVE-2026-15529
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py…
Patch available