CVE z tagiem deserialization — 200 wyników. ← Wszystkie tagi

CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8 CVSS
94.3% EPSS
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2026-20963 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
8.0% EPSS
CVE-2026-20131 🔴 Łataj teraz KEV
network

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected d…

10.0 CVSS
0.8% EPSS
CVE-2026-12569 🔴 Łataj teraz KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also a…

9.8 CVSS
1.1% EPSS
CVE-2024-52433 🔴 Łataj teraz

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.

9.8 CVSS
77.2% EPSS
CVE-2010-0094 🟡 Monitoruj

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via…

7.5 CVSS
87.0% EPSS
sundeserialization 2010-04-01
CVE-2021-4104 🟡 Monitoruj
appsos

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c…

7.5 CVSS
72.2% EPSS
CVE-2023-2249 🟠 Łataj w tym tygodniu

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten…

8.8 CVSS
48.2% EPSS
CVE-2019-17571 🔴 Łataj teraz
appsos

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t…

9.8 CVSS
33.8% EPSS
CVE-2024-24926 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a throu…

7.5 CVSS
42.1% EPSS
CVE-2024-52430 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.

9.8 CVSS
26.3% EPSS
lisdeserialization 2024-11-18
CVE-2025-27203 🟠 Łataj w tym tygodniu

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interacti…

9.6 CVSS
25.2% EPSS
CVE-2024-50507 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

9.8 CVSS
22.1% EPSS
deserialization 2024-10-30
CVE-2022-2437 🟠 Łataj w tym tygodniu

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possi…

9.8 CVSS
9.1% EPSS
CVE-2025-71260 🟠 Łataj w tym tygodniu

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary co…

8.8 CVSS
14.0% EPSS
CVE-2022-45047 🟠 Łataj w tym tygodniu
apps

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations th…

9.8 CVSS
5.7% EPSS
CVE-2024-52427 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Sca…

8.8 CVSS
9.4% EPSS
CVE-2026-26335 🟠 Łataj w tym tygodniu

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacke…

9.8 CVSS
2.8% EPSS
CVE-2026-34659 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker cou…

9.6 CVSS
3.5% EPSS
CVE-2022-29528 🔴 Łataj teraz

An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

9.8 CVSS
2.1% EPSS
CVE-2026-26142 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

9.8 CVSS
2.0% EPSS
CVE-2020-36718 🔴 Łataj teraz

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows una…

9.8 CVSS
1.8% EPSS
CVE-2024-25100 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.

10.0 CVSS
0.8% EPSS
CVE-2023-52218 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.

10.0 CVSS
0.8% EPSS
CVE-2023-52225 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: …

10.0 CVSS
0.8% EPSS
CVE-2024-30225 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.

10.0 CVSS
0.6% EPSS
deserialization 2024-03-28
CVE-2023-49778 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

10.0 CVSS
0.6% EPSS
dmrydeserialization 2023-12-21
CVE-2023-51505 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professi…

10.0 CVSS
0.6% EPSS
CVE-2026-33819 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

10.0 CVSS
0.4% EPSS
CVE-2026-41104 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

10.0 CVSS
0.3% EPSS
CVE-2023-49772 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a through 2.0.

10.0 CVSS
0.3% EPSS
CVE-2023-49773 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Tim Brattberg BCorp Shortcodes.This issue affects BCorp Shortcodes: from n/a through 0.23.

10.0 CVSS
0.3% EPSS
CVE-2023-52181 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

10.0 CVSS
0.3% EPSS
CVE-2023-51422 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create liv…

9.9 CVSS
0.8% EPSS
CVE-2023-51470 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

9.9 CVSS
0.8% EPSS
CVE-2026-43633 🟠 Łataj w tym tygodniu

HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achi…

10.0 CVSS
0.1% EPSS
deserialization 2026-05-19
CVE-2024-30228 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.

9.9 CVSS
0.6% EPSS
deserialization 2024-03-28
CVE-2023-52219 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

9.9 CVSS
0.6% EPSS
CVE-2024-47636 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.

9.8 CVSS
1.1% EPSS
CVE-2020-36726 🔴 Łataj teraz

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated…

9.8 CVSS
1.1% EPSS
CVE-2020-36727 🔴 Łataj teraz

The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed throug…

9.8 CVSS
1.1% EPSS
CVE-2025-66631 🟠 Łataj w tym tygodniu

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSeria…

9.8 CVSS
1.0% EPSS
CVE-2026-34838 🟠 Łataj w tym tygodniu

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserializatio…

9.9 CVSS
0.4% EPSS
deserializationrce 2026-04-02
CVE-2023-52182 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

9.9 CVSS
0.4% EPSS
CVE-2024-49625 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0.

9.8 CVSS
0.9% EPSS
CVE-2024-49318 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0.

9.8 CVSS
0.8% EPSS
deserialization 2024-10-17
CVE-2026-46386 🟠 Łataj w tym tygodniu

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookie…

9.9 CVSS
0.3% EPSS
deserialization 2026-06-26
CVE-2024-48030 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.

9.8 CVSS
0.8% EPSS
deserialization 2024-10-16
CVE-2026-56121 🟠 Łataj w tym tygodniu

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The us…

9.8 CVSS
0.8% EPSS
deserializationrce 2026-06-24
CVE-2024-49227 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2021-47952 🟠 Łataj w tym tygodniu

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft J…

9.8 CVSS
0.7% EPSS
deserializationrce 2026-05-16
CVE-2024-43354 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

9.8 CVSS
0.7% EPSS
deserialization 2024-08-19
CVE-2024-48026 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2024-48028 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2026-27303 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.6 CVSS
1.6% EPSS
CVE-2024-49626 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.This issue affects Shipyaari Shipping Management: from n/a through <= 1.2…

9.8 CVSS
0.6% EPSS
CVE-2024-49624 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1.

9.8 CVSS
0.6% EPSS
CVE-2026-31234 🟠 Łataj w tym tygodniu

Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication and authorization co…

9.8 CVSS
0.6% EPSS
deserializationrce 2026-05-12
CVE-2024-49218 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.

9.8 CVSS
0.6% EPSS
deserialization 2024-10-16
CVE-2026-8024 🟠 Łataj w tym tygodniu

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

9.8 CVSS
0.5% EPSS
deserialization 2026-06-18
CVE-2024-49332 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4.

9.8 CVSS
0.5% EPSS
CVE-2026-53874 🟠 Łataj w tym tygodniu

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malici…

9.8 CVSS
0.5% EPSS
deserialization 2026-06-17
CVE-2024-52432 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.

9.8 CVSS
0.5% EPSS
CVE-2025-62373 🔴 Łataj teraz

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, un…

9.8 CVSS
0.4% EPSS
CVE-2025-60230 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

9.8 CVSS
0.4% EPSS
deserialization 2026-06-17
CVE-2026-31214 🟠 Łataj w tym tygodniu

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load…

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-12
CVE-2026-31229 🟠 Łataj w tym tygodniu

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., mod…

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-12
CVE-2026-31237 🟠 Łataj w tym tygodniu

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines …

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-12
CVE-2025-39480 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer allows Object Injection.This issue affects Car Dealer: from n/a before 1.6.8.

9.8 CVSS
0.4% EPSS
deserialization 2025-05-23
CVE-2026-10042 🟠 Łataj w tym tygodniu

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /sim…

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-29
CVE-2026-7858 🟠 Łataj w tym tygodniu

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Rele…

9.8 CVSS
0.3% EPSS
deserializationrce 2026-06-01
CVE-2024-24797 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.

9.8 CVSS
0.3% EPSS
CVE-2024-48033 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.

9.8 CVSS
0.3% EPSS
deserialization 2024-10-11
CVE-2025-32897 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. Th…

9.8 CVSS
0.3% EPSS
CVE-2025-56422 🟠 Łataj w tym tygodniu

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

9.8 CVSS
0.2% EPSS
CVE-2026-34084 🔴 Łataj teraz

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument …

9.8 CVSS
0.2% EPSS
CVE-2026-40044 🟠 Łataj w tym tygodniu

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to…

9.8 CVSS
0.2% EPSS
deserialization 2026-04-13
CVE-2024-47552 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Severity Justification: The Apache Seata security team asses…

9.8 CVSS
0.1% EPSS
CVE-2026-25873 🟠 Łataj w tym tygodniu

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can…

9.8 CVSS
0.1% EPSS
deserializationrce 2026-03-18
CVE-2014-125112 🟠 Łataj w tym tygodniu

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execut…

9.8 CVSS
0.1% EPSS
CVE-2026-31072 🟠 Łataj w tym tygodniu

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitr…

9.8 CVSS
0.1% EPSS
deserializationrce 2026-05-19
CVE-2026-7637 🟠 Łataj w tym tygodniu

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for un…

9.8 CVSS
0.1% EPSS
deserialization 2026-05-20
CVE-2025-49380 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7…

9.8 CVSS
0.1% EPSS
deserialization 2025-10-22
CVE-2026-4851 🟠 Łataj w tym tygodniu

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to exe…

9.8 CVSS
0.1% EPSS
CVE-2025-59007 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a throu…

9.8 CVSS
0.1% EPSS
deserialization 2025-10-22
CVE-2026-26210 🔴 Łataj teraz

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deseria…

9.8 CVSS
0.1% EPSS
CVE-2025-60889 🔴 Łataj teraz

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

9.8 CVSS
0.1% EPSS
CVE-2026-31235 🟠 Łataj w tym tygodniu

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to deserialize data received via a m…

9.8 CVSS
0.1% EPSS
deserialization 2026-05-12
CVE-2026-31238 🟠 Łataj w tym tygodniu

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files usin…

9.8 CVSS
0.1% EPSS
deserializationrce 2026-05-12
CVE-2026-22500 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-22507 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24378 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24989 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25029 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25030 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25031 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25032 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25429 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27082 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27083 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27084 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27095 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat …

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32502 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32512 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25449 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Shinetheme Traveler allows Object Injection.This issue affects Traveler: from n/a before 3.2.8.1.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-18
CVE-2025-60233 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2025-60237 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2026-42472 🟠 Łataj w tym tygodniu

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.

9.8 CVSS
0.0% EPSS
deserialization 2026-05-01
CVE-2026-42473 🟠 Łataj w tym tygodniu

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.

9.8 CVSS
0.0% EPSS
deserialization 2026-05-01
CVE-2026-31239 🟠 Łataj w tym tygodniu

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to l…

9.8 CVSS
0.0% EPSS
deserialization 2026-05-12
CVE-2026-48207 🟠 Łataj w tym tygodniu

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application…

9.8 CVSS
0.0% EPSS
deserialization 2026-05-21
CVE-2026-3296 🟠 Łataj w tym tygodniu

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page…

9.8 CVSS
0.0% EPSS
deserialization 2026-04-08
CVE-2023-51414 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.

9.6 CVSS
0.6% EPSS
CVE-2022-3861 🟠 Łataj w tym tygodniu

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import…

8.8 CVSS
4.6% EPSS
CVE-2022-2434 🟡 Monitoruj

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users…

8.8 CVSS
4.2% EPSS
CVE-2023-51545 🟠 Łataj w tym tygodniu

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and recruitments.This issue affects Job Manager & Career – Manage job boar…

9.6 CVSS
0.2% EPSS
CVE-2023-52200 🟠 Łataj w tym tygodniu

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARM…

9.6 CVSS
0.2% EPSS
CVE-2026-34615 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.3 CVSS
1.6% EPSS
CVE-2024-49271 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimi…

9.1 CVSS
1.9% EPSS
CVE-2024-48042 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.

9.1 CVSS
1.9% EPSS
deserializationrce 2024-10-16
CVE-2022-2444 🟡 Monitoruj

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, and including 3.7.9. This makes it possi…

8.8 CVSS
2.7% EPSS
CVE-2022-23307 🟡 Monitoruj
appsos

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

8.8 CVSS
2.7% EPSS
CVE-2024-52434 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

9.1 CVSS
1.0% EPSS
CVE-2023-52205 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.

9.1 CVSS
0.5% EPSS
CVE-2023-52202 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.

9.1 CVSS
0.5% EPSS
CVE-2016-3415 🟠 Łataj w tym tygodniu

Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.

9.1 CVSS
0.5% EPSS
CVE-2023-52207 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.

9.1 CVSS
0.5% EPSS
CVE-2026-25923 🔴 Łataj teraz

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attacke…

9.1 CVSS
0.4% EPSS
CVE-2023-49777 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

9.1 CVSS
0.4% EPSS
CVE-2024-43252 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

9.0 CVSS
0.8% EPSS
deserialization 2024-08-19
CVE-2026-12046 🟠 Łataj w tym tygodniu

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module m…

9.0 CVSS
0.7% EPSS
deserializationrce 2026-06-19
CVE-2026-25769 🔴 Łataj teraz

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All …

9.1 CVSS
0.2% EPSS
CVE-2026-50076 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedLi…

9.1 CVSS
0.2% EPSS
CVE-2026-5426 🟠 Łataj w tym tygodniu

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via …

9.1 CVSS
0.1% EPSS
deserializationrce 2026-04-16
CVE-2026-27962 🔴 Łataj teraz

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrar…

9.1 CVSS
0.1% EPSS
CVE-2024-43242 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

9.0 CVSS
0.6% EPSS
CVE-2024-50408 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.

8.8 CVSS
1.5% EPSS
CVE-2026-9319 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

9.0 CVSS
0.2% EPSS
CVE-2024-30227 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.

9.0 CVSS
0.2% EPSS
deserialization 2024-03-28
CVE-2024-1872 🟡 Monitoruj

The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted input in the button_shortcode function. This makes it possible for authe…

8.8 CVSS
1.2% EPSS
deserialization 2024-03-29
CVE-2022-2436 🟡 Monitoruj

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attack…

8.8 CVSS
1.1% EPSS
CVE-2026-45484 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

8.8 CVSS
1.0% EPSS
CVE-2025-33244 🟠 Łataj w tym tygodniu

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A success…

9.0 CVSS
0.0% EPSS
deserializationdos 2026-03-24
CVE-2024-50416 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through …

8.8 CVSS
0.9% EPSS
CVE-2024-1770 🟡 Monitoruj

The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.2 via deserialization of untrusted input in the get_post_data function. This makes it possible for…

8.8 CVSS
0.9% EPSS
deserialization 2024-03-28
CVE-2024-2025 🟡 Monitoruj

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untruste…

8.8 CVSS
0.8% EPSS
deserialization 2024-03-23
CVE-2024-49226 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17.

8.8 CVSS
0.8% EPSS
deserialization 2024-10-16
CVE-2024-2693 🟡 Monitoruj

The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it p…

8.8 CVSS
0.8% EPSS
deserialization 2024-04-09
CVE-2022-23302 🟡 Monitoruj
appsos

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has ac…

8.8 CVSS
0.8% EPSS
CVE-2022-3568 🟡 Monitoruj

The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to cal…

8.8 CVSS
0.7% EPSS
CVE-2024-2008 🟡 Monitoruj

The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_…

8.8 CVSS
0.7% EPSS
deserialization 2024-04-04
CVE-2023-2500 🟡 Monitoruj

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortc…

8.8 CVSS
0.7% EPSS
CVE-2023-3343 🟡 Monitoruj

The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authentica…

8.8 CVSS
0.7% EPSS
CVE-2026-45659 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
0.6% EPSS
CVE-2026-20251 🟡 Monitoruj

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.…

8.8 CVSS
0.6% EPSS
CVE-2026-33110 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
0.6% EPSS
CVE-2026-33112 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
0.6% EPSS
CVE-2026-35439 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
0.6% EPSS
CVE-2026-40357 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
0.6% EPSS
CVE-2023-4386 🟡 Monitoruj

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attack…

8.1 CVSS
4.0% EPSS
CVE-2023-5583 🟠 Łataj w tym tygodniu

The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgaller…

8.8 CVSS
0.5% EPSS
CVE-2025-54920 🟠 Łataj w tym tygodniu
apps

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code e…

8.8 CVSS
0.5% EPSS
CVE-2026-31218 🟡 Monitoruj

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading …

8.8 CVSS
0.5% EPSS
deserializationrce 2026-05-12
CVE-2026-31219 🟡 Monitoruj

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user p…

8.8 CVSS
0.5% EPSS
deserializationrce 2026-05-12
CVE-2026-57527 🟡 Monitoruj

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malici…

8.8 CVSS
0.5% EPSS
deserializationrce 2026-06-26
CVE-2026-24954 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

8.8 CVSS
0.4% EPSS
deserialization 2026-02-03
CVE-2026-40901 🟠 Łataj w tym tygodniu

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserializ…

8.8 CVSS
0.4% EPSS
CVE-2025-39358 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Posts Carousel: from n/a through <= 1.3.12.

8.8 CVSS
0.3% EPSS
deserialization 2025-06-06
CVE-2026-31222 🟡 Monitoruj

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.load() without enabling…

8.8 CVSS
0.3% EPSS
CVE-2026-31223 🟡 Monitoruj

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler models using the unsafe…

8.8 CVSS
0.3% EPSS
CVE-2026-31224 🟡 Monitoruj

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files using torch.loa…

8.8 CVSS
0.3% EPSS
CVE-2026-31232 🟡 Monitoruj

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a use…

8.8 CVSS
0.2% EPSS
deserializationrce 2026-05-12
CVE-2024-22284 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

8.7 CVSS
0.7% EPSS
CVE-2025-53586 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through <= 1.9.1.

8.8 CVSS
0.1% EPSS
deserialization 2025-11-06
CVE-2025-60084 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Object Injection.This issue affects PDF for Elementor Forms + Drag An…

8.8 CVSS
0.1% EPSS
deserialization 2025-12-18
CVE-2026-24186 🟡 Monitoruj
os

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to cod…

8.8 CVSS
0.1% EPSS
CVE-2025-49386 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue affects Preserve Code Formatting: from n/a through <= 4.0.1.

8.8 CVSS
0.1% EPSS
deserialization 2025-11-06
CVE-2026-52751 🟠 Łataj w tym tygodniu

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a…

8.8 CVSS
0.1% EPSS
CVE-2026-27776 🟡 Monitoruj

IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on the system. Arbitrary code may be executed when some crafted f…

8.8 CVSS
0.1% EPSS
CVE-2026-3357 🟡 Monitoruj

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in th…

8.8 CVSS
0.1% EPSS
CVE-2025-11993 🟡 Monitoruj

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. Thi…

8.8 CVSS
0.1% EPSS
deserialization 2026-05-29
CVE-2026-24164 🟡 Monitoruj

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, an…

8.8 CVSS
0.1% EPSS
CVE-2026-40365 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
0.1% EPSS
CVE-2026-24974 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <= 3.7.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24976 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24978 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24981 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25358 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25359 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25360 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25400 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27045 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affects WooCommerce Infinite Scroll: from n/a through <= 1.6.2.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32513 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-1462 🟡 Monitoruj

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This …

8.8 CVSS
0.1% EPSS
deserialization 2026-04-13
CVE-2026-5127 🟡 Monitoruj

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This…

8.8 CVSS
0.1% EPSS
deserialization 2026-05-08
CVE-2026-32355 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-13
CVE-2026-25445 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-19
CVE-2026-32484 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25