Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2025-71345 picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71347 picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attacke… Mitigation only Fix from $1,9502026-07-04 HIGH 8.1 CVE-2025-71353 picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attack… Mitigation only Fix from $1,9502026-07-04 CRITICAL 9.8 CVE-2026-12481 A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la… Keras Mitigation only Fix from $2,3002026-07-03 MEDIUM 6.9 CVE-2026-13371 An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to th… Mitigation only Fix from $1,6002026-07-03 CRITICAL 9.8 CVE-2026-57677 Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-57621 Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. Mitigation only Fix from $2,3002026-07-02 HIGH 8.8 CVE-2026-56037 Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through… Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-27414 Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-27060 Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium:… Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-55153 mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its … Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-14265 Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an a… Advanced Jdbc Wrapper 4.0.1+ Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-51947 An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip)… Mitigation only Fix from $2,3002026-07-01 HIGH 8.8 CVE-2026-57516 Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution … Ray 2.56.0+ Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-58126 PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary fil… Pacsgear after 5.2.1 Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58127 PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj a… Pacsgear after 5.2.1 Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58025 Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Imp… Mediawiki 1.43.9 / 1.44.6+ Fix from $2,3002026-07-01 HIGH 7.8 CVE-2026-24247 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24250 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit o… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24251 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A suc… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24240 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24243 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24244 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24245 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 8.0 CVE-2026-10538 Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of … Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-56700 Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca… Mitigation only Fix from $2,3002026-06-30 MEDIUM 6.3 CVE-2026-55223 c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deser… Patch available Fix from $1,6002026-06-30 HIGH 8.1 CVE-2025-71349 picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected ma… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71350 picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed und… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71363 picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote a… Mitigation only Fix from $1,9502026-06-30