CVE z tagiem deserialization — 200 wyników. ← Wszystkie tagi

CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8 CVSS
94.3% EPSS
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2026-20963 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
8.0% EPSS
CVE-2026-20131 🔴 Łataj teraz KEV
network

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected d…

10.0 CVSS
0.8% EPSS
CVE-2024-52433 🔴 Łataj teraz

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.

9.8 CVSS
77.2% EPSS
CVE-2010-0094 🟡 Monitoruj

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via…

7.5 CVSS
87.0% EPSS
sundeserialization 2010-04-01
CVE-2023-2249 🟠 Łataj w tym tygodniu

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten…

8.8 CVSS
48.2% EPSS
CVE-2024-24926 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a throu…

7.5 CVSS
42.1% EPSS
CVE-2024-52430 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.

9.8 CVSS
26.3% EPSS
lisdeserialization 2024-11-18
CVE-2025-27203 🟠 Łataj w tym tygodniu

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interacti…

9.6 CVSS
25.2% EPSS
CVE-2024-50507 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

9.8 CVSS
22.1% EPSS
deserialization 2024-10-30
CVE-2022-2437 🟠 Łataj w tym tygodniu

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possi…

9.8 CVSS
9.1% EPSS
CVE-2025-71260 🟠 Łataj w tym tygodniu

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary co…

8.8 CVSS
14.0% EPSS
CVE-2022-45047 🟠 Łataj w tym tygodniu
apps

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations th…

9.8 CVSS
5.7% EPSS
CVE-2024-52427 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Sca…

8.8 CVSS
9.4% EPSS
CVE-2020-36718 🔴 Łataj teraz

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows una…

9.8 CVSS
1.8% EPSS
CVE-2024-25100 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.

10.0 CVSS
0.8% EPSS
CVE-2023-52218 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.

10.0 CVSS
0.8% EPSS
CVE-2023-52225 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: …

10.0 CVSS
0.8% EPSS
CVE-2024-30225 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.

10.0 CVSS
0.6% EPSS
deserialization 2024-03-28
CVE-2023-49778 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

10.0 CVSS
0.6% EPSS
dmrydeserialization 2023-12-21
CVE-2023-51505 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professi…

10.0 CVSS
0.6% EPSS
CVE-2023-49772 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a through 2.0.

10.0 CVSS
0.3% EPSS
CVE-2023-49773 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Tim Brattberg BCorp Shortcodes.This issue affects BCorp Shortcodes: from n/a through 0.23.

10.0 CVSS
0.3% EPSS
CVE-2023-52181 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

10.0 CVSS
0.3% EPSS
CVE-2023-51422 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create liv…

9.9 CVSS
0.8% EPSS
CVE-2023-51470 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

9.9 CVSS
0.8% EPSS
CVE-2024-30228 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.

9.9 CVSS
0.6% EPSS
deserialization 2024-03-28
CVE-2023-52219 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

9.9 CVSS
0.6% EPSS
CVE-2024-47636 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.

9.8 CVSS
1.1% EPSS
CVE-2020-36726 🔴 Łataj teraz

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated…

9.8 CVSS
1.1% EPSS
CVE-2020-36727 🔴 Łataj teraz

The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed throug…

9.8 CVSS
1.1% EPSS
CVE-2025-66631 🟠 Łataj w tym tygodniu

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSeria…

9.8 CVSS
1.0% EPSS
CVE-2026-34838 🟠 Łataj w tym tygodniu

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserializatio…

9.9 CVSS
0.4% EPSS
deserializationrce 2026-04-02
CVE-2023-52182 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

9.9 CVSS
0.4% EPSS
CVE-2024-49625 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0.

9.8 CVSS
0.9% EPSS
CVE-2024-49318 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0.

9.8 CVSS
0.8% EPSS
deserialization 2024-10-17
CVE-2024-48030 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.

9.8 CVSS
0.8% EPSS
deserialization 2024-10-16
CVE-2024-49227 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2024-43354 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

9.8 CVSS
0.7% EPSS
deserialization 2024-08-19
CVE-2024-48026 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2024-48028 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2026-27303 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.6 CVSS
1.6% EPSS
CVE-2024-49626 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.This issue affects Shipyaari Shipping Management: from n/a through <= 1.2…

9.8 CVSS
0.6% EPSS
CVE-2024-49624 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1.

9.8 CVSS
0.6% EPSS
CVE-2024-49218 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.

9.8 CVSS
0.6% EPSS
deserialization 2024-10-16
CVE-2024-49332 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4.

9.8 CVSS
0.5% EPSS
CVE-2024-52432 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.

9.8 CVSS
0.5% EPSS
CVE-2025-62373 🔴 Łataj teraz

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, un…

9.8 CVSS
0.4% EPSS
CVE-2025-39480 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer allows Object Injection.This issue affects Car Dealer: from n/a before 1.6.8.

9.8 CVSS
0.4% EPSS
deserialization 2025-05-23
CVE-2024-24797 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.

9.8 CVSS
0.3% EPSS
CVE-2024-48033 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.

9.8 CVSS
0.3% EPSS
deserialization 2024-10-11
CVE-2025-32897 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. Th…

9.8 CVSS
0.3% EPSS
CVE-2025-56422 🟠 Łataj w tym tygodniu

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

9.8 CVSS
0.2% EPSS
CVE-2026-40044 🟠 Łataj w tym tygodniu

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to…

9.8 CVSS
0.2% EPSS
deserialization 2026-04-13
CVE-2024-47552 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Severity Justification: The Apache Seata security team asses…

9.8 CVSS
0.1% EPSS
CVE-2026-25873 🟠 Łataj w tym tygodniu

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can…

9.8 CVSS
0.1% EPSS
deserializationrce 2026-03-18
CVE-2025-49380 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7…

9.8 CVSS
0.1% EPSS
deserialization 2025-10-22
CVE-2014-125112 🟠 Łataj w tym tygodniu

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execut…

9.8 CVSS
0.1% EPSS
deserializationrce 2026-03-26
CVE-2026-4851 🟠 Łataj w tym tygodniu

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to exe…

9.8 CVSS
0.1% EPSS
CVE-2025-59007 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a throu…

9.8 CVSS
0.1% EPSS
deserialization 2025-10-22
CVE-2026-22500 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-22507 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24378 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24989 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25029 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25030 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25031 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25032 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25429 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27082 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27083 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27084 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27095 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat …

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32502 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32512 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2025-60889 🟠 Łataj w tym tygodniu

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

9.8 CVSS
0.1% EPSS
deserialization 2026-04-28
CVE-2026-25449 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Shinetheme Traveler allows Object Injection.This issue affects Traveler: from n/a before 3.2.8.1.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-18
CVE-2025-60233 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2025-60237 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2026-3296 🟠 Łataj w tym tygodniu

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page…

9.8 CVSS
0.0% EPSS
deserialization 2026-04-08
CVE-2023-51414 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.

9.6 CVSS
0.6% EPSS
CVE-2022-3861 🟠 Łataj w tym tygodniu

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import…

8.8 CVSS
4.6% EPSS
CVE-2022-2434 🟡 Monitoruj

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users…

8.8 CVSS
4.2% EPSS
CVE-2023-51545 🟠 Łataj w tym tygodniu

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and recruitments.This issue affects Job Manager & Career – Manage job boar…

9.6 CVSS
0.2% EPSS
CVE-2023-52200 🟠 Łataj w tym tygodniu

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARM…

9.6 CVSS
0.2% EPSS
CVE-2026-34615 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.3 CVSS
1.6% EPSS
CVE-2024-49271 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimi…

9.1 CVSS
1.9% EPSS
CVE-2024-48042 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.

9.1 CVSS
1.9% EPSS
deserializationrce 2024-10-16
CVE-2022-2444 🟡 Monitoruj

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, and including 3.7.9. This makes it possi…

8.8 CVSS
2.7% EPSS
CVE-2024-52434 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

9.1 CVSS
1.0% EPSS
CVE-2023-52205 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.

9.1 CVSS
0.5% EPSS
CVE-2023-52202 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.

9.1 CVSS
0.5% EPSS
CVE-2023-52207 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.

9.1 CVSS
0.5% EPSS
CVE-2023-49777 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

9.1 CVSS
0.4% EPSS
CVE-2024-43252 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

9.0 CVSS
0.8% EPSS
deserialization 2024-08-19
CVE-2026-25769 🔴 Łataj teraz

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All …

9.1 CVSS
0.2% EPSS
CVE-2026-25923 🔴 Łataj teraz

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attacke…

9.1 CVSS
0.1% EPSS
CVE-2026-27962 🔴 Łataj teraz

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrar…

9.1 CVSS
0.1% EPSS
CVE-2024-43242 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

9.0 CVSS
0.6% EPSS
CVE-2024-50408 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.

8.8 CVSS
1.5% EPSS
CVE-2024-30227 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.

9.0 CVSS
0.2% EPSS
deserialization 2024-03-28
CVE-2024-1872 🟡 Monitoruj

The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted input in the button_shortcode function. This makes it possible for authe…

8.8 CVSS
1.2% EPSS
deserialization 2024-03-29
CVE-2022-2436 🟡 Monitoruj

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attack…

8.8 CVSS
1.1% EPSS
CVE-2025-33244 🟠 Łataj w tym tygodniu

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A success…

9.0 CVSS
0.0% EPSS
deserializationdos 2026-03-24
CVE-2024-50416 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through …

8.8 CVSS
0.9% EPSS
CVE-2024-1770 🟡 Monitoruj

The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.2 via deserialization of untrusted input in the get_post_data function. This makes it possible for…

8.8 CVSS
0.9% EPSS
deserialization 2024-03-28
CVE-2024-2025 🟡 Monitoruj

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untruste…

8.8 CVSS
0.8% EPSS
deserialization 2024-03-23
CVE-2024-49226 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17.

8.8 CVSS
0.8% EPSS
deserialization 2024-10-16
CVE-2024-2693 🟡 Monitoruj

The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it p…

8.8 CVSS
0.8% EPSS
deserialization 2024-04-09
CVE-2022-3568 🟡 Monitoruj

The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to cal…

8.8 CVSS
0.7% EPSS
CVE-2024-2008 🟡 Monitoruj

The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_…

8.8 CVSS
0.7% EPSS
deserialization 2024-04-04
CVE-2023-2500 🟡 Monitoruj

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortc…

8.8 CVSS
0.7% EPSS
CVE-2023-3343 🟡 Monitoruj

The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authentica…

8.8 CVSS
0.7% EPSS
CVE-2023-4386 🟡 Monitoruj

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attack…

8.1 CVSS
4.0% EPSS
CVE-2023-5583 🟠 Łataj w tym tygodniu

The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgaller…

8.8 CVSS
0.5% EPSS
CVE-2025-54920 🟠 Łataj w tym tygodniu
apps

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code e…

8.8 CVSS
0.5% EPSS
CVE-2026-40901 🟠 Łataj w tym tygodniu

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserializ…

8.8 CVSS
0.4% EPSS
CVE-2025-39358 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Posts Carousel: from n/a through <= 1.3.12.

8.8 CVSS
0.3% EPSS
deserialization 2025-06-06
CVE-2024-22284 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

8.7 CVSS
0.7% EPSS
CVE-2025-53586 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through <= 1.9.1.

8.8 CVSS
0.1% EPSS
deserialization 2025-11-06
CVE-2025-60084 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Object Injection.This issue affects PDF for Elementor Forms + Drag An…

8.8 CVSS
0.1% EPSS
deserialization 2025-12-18
CVE-2025-49386 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue affects Preserve Code Formatting: from n/a through <= 4.0.1.

8.8 CVSS
0.1% EPSS
deserialization 2025-11-06
CVE-2026-27776 🟡 Monitoruj

IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on the system. Arbitrary code may be executed when some crafted f…

8.8 CVSS
0.1% EPSS
CVE-2026-3357 🟡 Monitoruj

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in th…

8.8 CVSS
0.1% EPSS
CVE-2026-24164 🟡 Monitoruj

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, an…

8.8 CVSS
0.1% EPSS
CVE-2026-24974 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <= 3.7.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24976 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24978 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24981 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25358 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25359 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25360 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25400 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27045 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affects WooCommerce Infinite Scroll: from n/a through <= 1.6.2.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32513 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-1462 🟡 Monitoruj

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This …

8.8 CVSS
0.1% EPSS
deserialization 2026-04-13
CVE-2026-32355 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-13
CVE-2026-25445 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-19
CVE-2026-32484 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.

8.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2025-68853 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: from n/a through <= 9.1.1.

8.8 CVSS
0.1% EPSS
deserialization 2026-02-20
CVE-2024-23513 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.

8.7 CVSS
0.5% EPSS
CVE-2025-50004 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.

8.8 CVSS
0.0% EPSS
deserialization 2026-01-22
CVE-2024-24842 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.…

8.7 CVSS
0.4% EPSS
deserialization 2024-03-27
CVE-2024-31277 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.

8.7 CVSS
0.4% EPSS
deserialization 2024-04-07
CVE-2024-23512 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks: from n/a through 3.…

8.7 CVSS
0.4% EPSS
CVE-2024-22309 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

8.7 CVSS
0.3% EPSS
CVE-2026-35554 🟡 Monitoruj

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network…

8.7 CVSS
0.0% EPSS
deserialization 2026-04-07
CVE-2023-4402 🟠 Łataj w tym tygodniu

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated att…

8.1 CVSS
2.9% EPSS
CVE-2024-29136 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.

8.5 CVSS
0.5% EPSS
CVE-2023-37390 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.

8.3 CVSS
0.2% EPSS
CVE-2023-34027 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Viewed Products: from n/a through 1.0.0.

8.3 CVSS
0.2% EPSS
CVE-2023-40555 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.

8.3 CVSS
0.1% EPSS
CVE-2023-28782 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.

8.3 CVSS
0.1% EPSS
CVE-2024-24796 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for W…

8.2 CVSS
0.4% EPSS
CVE-2023-23649 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a through 2.1.

8.1 CVSS
0.7% EPSS
deserialization 2024-03-28
CVE-2023-49826 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Them…

8.1 CVSS
0.7% EPSS
CVE-2023-32795 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.

8.2 CVSS
0.2% EPSS
CVE-2026-24009 🟡 Monitoruj

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-143…

8.1 CVSS
0.3% EPSS
CVE-2024-30229 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.

8.0 CVSS
0.6% EPSS
CVE-2026-41316 🟡 Monitoruj

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object i…

8.1 CVSS
0.1% EPSS
deserialization 2026-04-24
CVE-2026-25524 🟡 Monitoruj

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.…

8.1 CVSS
0.1% EPSS
deserializationrce 2026-04-20
CVE-2026-22505 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Records: from n/a through <= 1.2.

8.1 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-22510 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue affects Melody: from n/a through <= 1.6.3.

8.1 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-23971 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8.

8.1 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27096 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through…

8.1 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2026-32184 🟡 Monitoruj

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.

7.8 CVSS
0.4% EPSS
deserialization 2026-04-14
CVE-2026-32192 🟡 Monitoruj

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

7.8 CVSS
0.4% EPSS
deserialization 2026-04-14
CVE-2022-3342 🟡 Monitoruj

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function…

7.5 CVSS
1.6% EPSS
CVE-2026-24141 🟡 Monitoruj

NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A successful exploit of…

7.8 CVSS
0.1% EPSS
deserialization 2026-03-24
CVE-2026-24165 🟡 Monitoruj

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, an…

7.8 CVSS
0.0% EPSS
CVE-2024-2229 🟡 Monitoruj

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a valid user.

7.8 CVSS
0.0% EPSS
deserialization 2024-03-18
CVE-2026-4416 🟡 Monitoruj

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting …

7.8 CVSS
0.0% EPSS
CVE-2026-3989 🟡 Monitoruj

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attacke…

7.8 CVSS
0.0% EPSS
deserialization 2026-03-12
CVE-2023-52206 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

7.7 CVSS
0.4% EPSS
CVE-2022-2442 🟡 Monitoruj

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticat…

7.2 CVSS
2.8% EPSS
CVE-2024-2501 🟡 Monitoruj

The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_u…

7.5 CVSS
1.2% EPSS
deserialization 2024-04-09
CVE-2024-1951 🟡 Monitoruj

The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization via shortcode of untrusted in…

7.5 CVSS
0.9% EPSS
deserialization 2024-03-13
CVE-2024-1792 🟡 Monitoruj

The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted input from the text_datetime_timestamp_timezone field. This makes it possi…

7.5 CVSS
0.7% EPSS
deserialization 2024-04-09
CVE-2026-34202 🟡 Monitoruj

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Ze…

7.5 CVSS
0.3% EPSS
zfnddeserialization 2026-03-31
CVE-2023-49819 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.

7.5 CVSS
0.3% EPSS
CVE-2023-32513 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.

7.5 CVSS
0.3% EPSS
CVE-2026-21619 🟡 Monitoruj

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessi…

7.5 CVSS
0.1% EPSS
hexdeserialization 2026-02-27
CVE-2026-5426 🟡 Monitoruj

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via …

7.5 CVSS
0.1% EPSS
deserializationrce 2026-04-16
CVE-2026-23957 🟡 Monitoruj

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding encoded array lengths by replacing them with an excessively large val…

7.5 CVSS
0.0% EPSS
CVE-2026-24006 🟡 Monitoruj

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack li…

7.5 CVSS
0.0% EPSS
CVE-2022-2438 🟡 Monitoruj

The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with…

7.2 CVSS
1.3% EPSS
CVE-2023-46147 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

7.4 CVSS
0.2% EPSS
CVE-2024-3020 🟡 Monitoruj

The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function via the 'shortcode' parameter. This allows authenticated attackers, wi…

7.2 CVSS
1.2% EPSS
deserialization 2024-04-10
CVE-2024-49684 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.…

7.2 CVSS
0.8% EPSS
deserialization 2024-10-23
CVE-2026-5536 🟡 Monitoruj

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack…

7.3 CVSS
0.1% EPSS
CVE-2026-24156 🟡 Monitoruj

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

7.3 CVSS
0.1% EPSS
deserializationrce 2026-04-07
CVE-2026-4860 🟡 Monitoruj

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java o…

7.3 CVSS
0.0% EPSS
deserialization 2026-03-26
CVE-2026-3328 🟡 Monitoruj

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the …

7.2 CVSS
0.5% EPSS
deserializationrce 2026-03-26
CVE-2024-52393 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.

7.2 CVSS
0.5% EPSS
CVE-2025-26885 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.

7.2 CVSS
0.2% EPSS
deserialization 2025-03-03
CVE-2025-66073 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.

7.2 CVSS
0.1% EPSS
deserialization 2025-11-21
CVE-2025-68038 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through < 5.9.14.

7.2 CVSS
0.1% EPSS
deserialization 2025-12-24
CVE-2026-29109 🟡 Monitoruj

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter proce…

7.2 CVSS
0.1% EPSS