Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2025-71345
picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can…
Mitigation only
HIGH 8.1
CVE-2025-71347
picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attacke…
Mitigation only
HIGH 8.1
CVE-2025-71353
picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attack…
Mitigation only
CRITICAL 9.8
CVE-2026-12481
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la…
Keras
Mitigation only
MEDIUM 6.9
CVE-2026-13371
An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to th…
Mitigation only
CRITICAL 9.8
CVE-2026-57677
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
Mitigation only
CRITICAL 9.8
CVE-2026-57621
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Mitigation only
HIGH 8.8
CVE-2026-56037
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection.
This issue affects Themify Popup: from n/a through…
Mitigation only
HIGH 8.8
CVE-2026-27414
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Mitigation only
HIGH 8.8
CVE-2026-27060
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection.
This issue affects ARMember Premium:…
Mitigation only
HIGH 7.1
CVE-2026-55153
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its …
Mitigation only
HIGH 8.8
CVE-2026-14265
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an a…
Advanced Jdbc Wrapper
4.0.1+
CRITICAL 9.8
CVE-2026-51947
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip)…
Mitigation only
HIGH 8.8
CVE-2026-57516
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution …
Ray
2.56.0+
CRITICAL 9.8
CVE-2026-58126
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary fil…
Pacsgear
after 5.2.1
CRITICAL 9.8
CVE-2026-58127
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj a…
Pacsgear
after 5.2.1
CRITICAL 9.8
CVE-2026-58025
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Imp…
Mediawiki
1.43.9 / 1.44.6+
HIGH 7.8
CVE-2026-24247
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…
Nemo Megatron Bridge
0.4.1+
HIGH 7.8
CVE-2026-24250
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit o…
Nemo Megatron Bridge
0.4.1+
HIGH 7.8
CVE-2026-24251
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A suc…
Nemo Megatron Bridge
0.4.1+
HIGH 7.8
CVE-2026-24240
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…
Nemo Megatron Bridge
0.4.1+
HIGH 7.8
CVE-2026-24243
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…
Nemo Megatron Bridge
0.4.1+
HIGH 7.8
CVE-2026-24244
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…
Nemo Megatron Bridge
0.4.1+
HIGH 7.8
CVE-2026-24245
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…
Nemo Megatron Bridge
0.4.1+
HIGH 8.0
CVE-2026-10538
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of …
Mitigation only
CRITICAL 9.8
CVE-2026-56700
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca…
Mitigation only
MEDIUM 6.3
CVE-2026-55223
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deser…
Patch available
HIGH 8.1
CVE-2025-71349
picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected ma…
Mitigation only
HIGH 8.1
CVE-2025-71350
picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed und…
Mitigation only
HIGH 8.1
CVE-2025-71363
picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote a…
Mitigation only