Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.3 CVE-2026-58281 Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-11 HIGH 7.5 CVE-2026-55175 Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respecti… Spinnaker 2025.3.4 / 2025.4.4+ Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-44795 Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing by… Spinnaker 2025.3.3 / 2025.4.4+ Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-54469 Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker w… Unisphere For Powermax 10.3.0.7+ Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-59827 Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances w… Metabase 0.58.15 / 0.59.12+ Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-54499 Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza mo… Stanza 1.12.2+ Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-15105 A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp … No fix yet Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-33264 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server … Airflow 3.3.0+ Fix from $2,3002026-07-07 HIGH 7.3 CVE-2026-43825EPSS 9% Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu… Opennlp Mitigation only Fix from $1,9502026-07-06 HIGH 8.8 CVE-2026-46590 Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetada… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-43867 Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 HIGH 8.1 CVE-2026-40859 Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Conte… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-42527 Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components … Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-43865 Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast ins… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-43866 Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the … Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-14723 A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the… Patch available Fix from $1,6002026-07-05 HIGH 8.2 CVE-2026-14637 A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affecte… Patch available Fix from $1,9502026-07-04 HIGH 8.8 CVE-2026-14534 Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in t… Fickling after 0.1.10 Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71372 Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code executio… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71375 picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can cr… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71356 picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71359 picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing re… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71360 picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed unde… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71362 picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can … Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71364 picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote c… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71366 picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71367 picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71369 picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, al… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71342 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71343 picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce met… Mitigation only Fix from $1,9502026-07-04