Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2025-71368 picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code.… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71371 picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pick… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71374 picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to e… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-7871 IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all sec… Langflow after 1.10.0 Fix from $2,3002026-06-30 HIGH 8.8 CVE-2026-13759 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStre… Websphere Extreme Scale after 8.6.1.6 Fix from $1,9502026-06-30 HIGH 8.4 CVE-2026-12578 The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code. No fix yet Fix from $1,9502026-06-30 HIGH 8.0 CVE-2026-12240 The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize functi… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.9 CVE-2026-46386 OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_… Mitigation only Fix from $2,3002026-06-26 HIGH 8.8 CVE-2026-57527 Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxi… Patch available Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2026-56057 Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. Mitigation only Fix from $2,3002026-06-26 HIGH 8.8 CVE-2026-56055 Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 8.1 CVE-2026-56031 Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2026-56032 Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-53914 In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata Kotlin 2.4.20+ Fix from $2,3002026-06-26 HIGH 8.1 CVE-2025-71340 picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attac… Mitigation only Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-46607 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache… Mitigation only Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-56053 Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-10043 MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Patch available Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-56121 Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code exe… Patch available Fix from $2,3002026-06-24 HIGH 8.1 CVE-2025-71354 picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Atta… Mitigation only Fix from $1,9502026-06-24 HIGH 8.1 CVE-2026-54512 jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4,… Jackson Databind 2.18.8 / 2.21.4+ Fix from $1,9502026-06-23 HIGH 8.8 CVE-2026-41862 Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforc… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-39253 An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Serv… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2025-71341 picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected mali… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2025-71365 picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attack… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2025-71370 picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers ca… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2025-71376 picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attacker… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-48517 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePack… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-48502 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based o… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 HIGH 8.1 CVE-2025-71339 Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execut… Mitigation only Fix from $1,9502026-06-22