Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2025-71344 picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, … Mitigation only Fix from $1,9502026-06-22 HIGH 8.1 CVE-2025-71358 picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods.… Mitigation only Fix from $1,9502026-06-22 CRITICAL 9.2 CVE-2026-45034 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohi… No fix yet Fix from $2,3002026-06-22 HIGH 7.8 CVE-2025-71357 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can… Picklescan 0.0.30+ Fix from $1,9502026-06-21 HIGH 7.8 CVE-2025-71378 picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. … Picklescan 0.0.30+ Fix from $1,9502026-06-21 HIGH 7.8 CVE-2025-71348 picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. At… Picklescan 0.0.28+ Fix from $1,9502026-06-21 MEDIUM 6.3 CVE-2026-12787 A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part o… Mitigation only Fix from $1,6002026-06-21 MEDIUM 6.5 CVE-2026-56304 picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file… Picklescan 1.0.1+ Fix from $1,6002026-06-20 CRITICAL 9.5 CVE-2026-48909EPSS 8% SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to … Mitigation only Fix from $2,3002026-06-20 HIGH 8.1 CVE-2026-49286 PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the o… Patch available Fix from $1,9502026-06-19 CRITICAL 9.0 CVE-2026-12046 Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat… Pgadmin 4 9.16+ Fix from $2,3002026-06-19 HIGH 7.2 CVE-2025-27511 GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extens… Geoserver 2.27.0+ Fix from $1,9502026-06-18 CRITICAL 9.8 CVE-2026-8024 A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access t… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-12569 KEVEPSS 30% A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t… Flexplm 11.0m030+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-53805 NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /… Patch available Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-53874 picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval call… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-71321 picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-49108 Unauthenticated PHP Object Injection in Moderno < 1.43 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.1 CVE-2026-40733 Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-40738 Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-40752 Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-40756 Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-40757 Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39556 Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39560 Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39576 Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39442 Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-39445 Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.8 CVE-2025-69127 Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.8 CVE-2025-69130 Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. Mitigation only Fix from $1,9502026-06-17