CVE z tagiem deserialization — 200 wyników. ← Wszystkie tagi

CVE-2025-10035 🔴 Łataj teraz KEV

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to …

10.0 CVSS
99.6% EPSS
CVE-2025-53770 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Micro…

9.8 CVSS
100.0% EPSS
CVE-2021-42237 🔴 Łataj teraz KEV

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special config…

9.8 CVSS
97.9% EPSS
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8 CVSS
90.7% EPSS
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2021-23758 🔴 Łataj teraz KEV

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

8.1 CVSS
83.6% EPSS
CVE-2026-12569 🔴 Łataj teraz KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also a…

9.8 CVSS
30.2% EPSS
CVE-2025-23006 🔴 Łataj teraz KEV
network

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentiall…

9.8 CVSS
23.4% EPSS
CVE-2026-20963 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
8.0% EPSS
CVE-2026-20131 🔴 Łataj teraz KEV
network

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected d…

10.0 CVSS
0.8% EPSS
CVE-2026-58644 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

9.8 CVSS
1.5% EPSS
CVE-2026-45659 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
3.2% EPSS
CVE-2024-52433 🔴 Łataj teraz

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.

9.8 CVSS
77.2% EPSS
CVE-2010-0094 🟡 Monitoruj

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via…

7.5 CVSS
87.0% EPSS
sundeserialization 2010-04-01
CVE-2021-4104 🟡 Monitoruj
appsos

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c…

7.5 CVSS
72.2% EPSS
CVE-2023-2249 🟠 Łataj w tym tygodniu

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten…

8.8 CVSS
48.2% EPSS
CVE-2020-9484 🟡 Monitoruj
apps

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is …

7.0 CVSS
56.6% EPSS
CVE-2019-17571 🔴 Łataj teraz
appsos

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t…

9.8 CVSS
33.8% EPSS
CVE-2024-24926 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a throu…

7.5 CVSS
42.1% EPSS
CVE-2025-71260 🟠 Łataj w tym tygodniu

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary co…

8.8 CVSS
34.4% EPSS
CVE-2024-52430 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.

9.8 CVSS
26.3% EPSS
lisdeserialization 2024-11-18
CVE-2025-27203 🟠 Łataj w tym tygodniu

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interacti…

9.6 CVSS
25.2% EPSS
CVE-2024-50507 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

9.8 CVSS
22.1% EPSS
deserialization 2024-10-30
CVE-2026-50522 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

9.8 CVSS
20.3% EPSS
CVE-2026-25874 🔴 Łataj teraz

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the polic…

9.8 CVSS
15.6% EPSS
CVE-2026-33439 🔴 Łataj teraz

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.c…

9.8 CVSS
10.5% EPSS
CVE-2022-2437 🟠 Łataj w tym tygodniu

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possi…

9.8 CVSS
9.1% EPSS
CVE-2022-45047 🟠 Łataj w tym tygodniu
apps

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations th…

9.8 CVSS
5.7% EPSS
CVE-2024-52427 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Sca…

8.8 CVSS
9.4% EPSS
CVE-2024-44902 🟠 Łataj w tym tygodniu

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

9.8 CVSS
4.2% EPSS
CVE-2020-26867 🟠 Łataj w tym tygodniu

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

9.8 CVSS
3.7% EPSS
CVE-2026-3296 🟠 Łataj w tym tygodniu

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page…

9.8 CVSS
3.5% EPSS
deserialization 2026-04-08
CVE-2026-26335 🟠 Łataj w tym tygodniu

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacke…

9.8 CVSS
2.8% EPSS
CVE-2026-69836 🟠 Łataj w tym tygodniu

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

10.0 CVSS
1.6% EPSS
deserialization 2026-08-20
CVE-2022-29528 🔴 Łataj teraz

An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

9.8 CVSS
2.1% EPSS
CVE-2026-43633 🟠 Łataj w tym tygodniu

HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achi…

10.0 CVSS
1.1% EPSS
deserialization 2026-05-19
CVE-2026-26142 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

9.8 CVSS
2.0% EPSS
CVE-2026-41104 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

10.0 CVSS
0.9% EPSS
CVE-2020-36718 🔴 Łataj teraz

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows una…

9.8 CVSS
1.8% EPSS
CVE-2024-25100 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.

10.0 CVSS
0.8% EPSS
CVE-2023-52218 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.

10.0 CVSS
0.8% EPSS
CVE-2023-52225 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: …

10.0 CVSS
0.8% EPSS
CVE-2026-66713 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is …

9.8 CVSS
1.8% EPSS
CVE-2026-59124 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

9.8 CVSS
1.7% EPSS
CVE-2024-30225 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.

10.0 CVSS
0.6% EPSS
deserialization 2024-03-28
CVE-2023-49778 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

10.0 CVSS
0.6% EPSS
dmrydeserialization 2023-12-21
CVE-2023-51505 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professi…

10.0 CVSS
0.6% EPSS
CVE-2026-34838 🟠 Łataj w tym tygodniu

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserializatio…

9.9 CVSS
1.0% EPSS
CVE-2026-11756 🟠 Łataj w tym tygodniu

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code …

10.0 CVSS
0.4% EPSS
deserializationrce 2026-07-28
CVE-2026-50515 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

9.9 CVSS
0.9% EPSS
CVE-2026-33819 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

10.0 CVSS
0.4% EPSS
CVE-2023-49772 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a through 2.0.

10.0 CVSS
0.3% EPSS
CVE-2023-49773 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Tim Brattberg BCorp Shortcodes.This issue affects BCorp Shortcodes: from n/a through 0.23.

10.0 CVSS
0.3% EPSS
CVE-2023-52181 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

10.0 CVSS
0.3% EPSS
CVE-2023-51422 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create liv…

9.9 CVSS
0.8% EPSS
CVE-2023-51470 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

9.9 CVSS
0.8% EPSS
CVE-2026-18948 🟠 Łataj w tym tygodniu

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, l…

9.9 CVSS
0.7% EPSS
deserializationrce 2026-08-10
CVE-2026-54118 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

9.8 CVSS
1.2% EPSS
CVE-2026-54117 🟠 Łataj w tym tygodniu
appscloud

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

9.8 CVSS
1.2% EPSS
CVE-2024-30228 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.

9.9 CVSS
0.6% EPSS
deserialization 2024-03-28
CVE-2023-52219 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

9.9 CVSS
0.6% EPSS
CVE-2026-25873 🟠 Łataj w tym tygodniu

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can…

9.8 CVSS
1.1% EPSS
deserializationrce 2026-03-18
CVE-2024-47636 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.

9.8 CVSS
1.1% EPSS
CVE-2020-36726 🔴 Łataj teraz

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated…

9.8 CVSS
1.1% EPSS
CVE-2020-36727 🔴 Łataj teraz

The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed throug…

9.8 CVSS
1.1% EPSS
CVE-2025-66631 🟠 Łataj w tym tygodniu

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSeria…

9.8 CVSS
1.0% EPSS
CVE-2026-40860 🟠 Łataj w tym tygodniu
apps

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any …

9.8 CVSS
0.9% EPSS
CVE-2023-52182 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

9.9 CVSS
0.4% EPSS
CVE-2024-49625 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0.

9.8 CVSS
0.9% EPSS
CVE-2024-49318 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0.

9.8 CVSS
0.8% EPSS
deserialization 2024-10-17
CVE-2026-31072 🟠 Łataj w tym tygodniu

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitr…

9.8 CVSS
0.8% EPSS
deserializationrce 2026-05-19
CVE-2026-46386 🟠 Łataj w tym tygodniu

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookie…

9.9 CVSS
0.3% EPSS
deserialization 2026-06-26
CVE-2024-48030 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.

9.8 CVSS
0.8% EPSS
deserialization 2024-10-16
CVE-2026-56121 🟠 Łataj w tym tygodniu

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The us…

9.8 CVSS
0.8% EPSS
deserializationrce 2026-06-24
CVE-2026-71558 🟠 Łataj w tym tygodniu
apps

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic…

9.8 CVSS
0.7% EPSS
CVE-2024-49227 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2026-26210 🔴 Łataj teraz

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deseria…

9.8 CVSS
0.7% EPSS
CVE-2021-47952 🟠 Łataj w tym tygodniu

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft J…

9.8 CVSS
0.7% EPSS
deserializationrce 2026-05-16
CVE-2024-43354 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

9.8 CVSS
0.7% EPSS
deserialization 2024-08-19
CVE-2024-48026 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2024-48028 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.

9.8 CVSS
0.7% EPSS
deserialization 2024-10-16
CVE-2026-66909 🟠 Łataj w tym tygodniu
apps

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destinati…

9.8 CVSS
0.7% EPSS
CVE-2026-64606 🟠 Łataj w tym tygodniu
apps

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from bef…

9.8 CVSS
0.6% EPSS
CVE-2026-27303 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.6 CVSS
1.6% EPSS
CVE-2026-10042 🟠 Łataj w tym tygodniu

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /sim…

9.8 CVSS
0.6% EPSS
deserializationrce 2026-05-29
CVE-2026-68771 🟠 Łataj w tym tygodniu

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and trigge…

9.8 CVSS
0.6% EPSS
deserialization 2026-07-31
CVE-2024-49626 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.This issue affects Shipyaari Shipping Management: from n/a through <= 1.2…

9.8 CVSS
0.6% EPSS
CVE-2024-49624 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1.

9.8 CVSS
0.6% EPSS
CVE-2026-31234 🟠 Łataj w tym tygodniu

Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication and authorization co…

9.8 CVSS
0.6% EPSS
deserializationrce 2026-05-12
CVE-2024-49218 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.

9.8 CVSS
0.6% EPSS
deserialization 2024-10-16
CVE-2026-7637 🟠 Łataj w tym tygodniu

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for un…

9.8 CVSS
0.6% EPSS
deserialization 2026-05-20
CVE-2026-48207 🟠 Łataj w tym tygodniu
apps

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application…

9.8 CVSS
0.6% EPSS
CVE-2026-57724 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

9.8 CVSS
0.6% EPSS
deserialization 2026-07-13
CVE-2026-57738 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

9.8 CVSS
0.6% EPSS
deserialization 2026-07-13
CVE-2026-57744 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

9.8 CVSS
0.6% EPSS
deserialization 2026-07-13
CVE-2026-57770 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

9.8 CVSS
0.6% EPSS
deserialization 2026-07-13
CVE-2026-59518 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

9.8 CVSS
0.6% EPSS
deserialization 2026-07-13
CVE-2026-8024 🟠 Łataj w tym tygodniu

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

9.8 CVSS
0.5% EPSS
deserialization 2026-06-18
CVE-2026-61484 🟠 Łataj w tym tygodniu
apps

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes t…

9.8 CVSS
0.5% EPSS
CVE-2026-41586 🔴 Łataj teraz

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeCh…

9.8 CVSS
0.5% EPSS
CVE-2024-49332 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4.

9.8 CVSS
0.5% EPSS
CVE-2026-53874 🟠 Łataj w tym tygodniu

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malici…

9.8 CVSS
0.5% EPSS
deserialization 2026-06-17
CVE-2026-14512 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

9.8 CVSS
0.5% EPSS
CVE-2024-13784 🟠 Łataj w tym tygodniu

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submis…

9.8 CVSS
0.5% EPSS
deserialization 2026-08-16
CVE-2026-69098 🟠 Łataj w tym tygodniu

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON inp…

9.8 CVSS
0.5% EPSS
deserializationrce 2026-08-04
CVE-2026-58025 🟠 Łataj w tym tygodniu

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Loggin…

9.8 CVSS
0.5% EPSS
CVE-2026-12118 🟠 Łataj w tym tygodniu

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

9.8 CVSS
0.5% EPSS
ibmdeserialization 2026-07-30
CVE-2025-60889 🔴 Łataj teraz

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

9.8 CVSS
0.5% EPSS
CVE-2024-52432 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.

9.8 CVSS
0.5% EPSS
CVE-2026-16258 🟠 Łataj w tym tygodniu

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via a…

9.8 CVSS
0.5% EPSS
deserializationrce 2026-08-07
CVE-2025-62373 🔴 Łataj teraz

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, un…

9.8 CVSS
0.4% EPSS
CVE-2025-60230 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

9.8 CVSS
0.4% EPSS
deserialization 2026-06-17
CVE-2026-12481 🔴 Łataj teraz

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function f…

9.8 CVSS
0.4% EPSS
CVE-2026-31214 🟠 Łataj w tym tygodniu

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load…

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-12
CVE-2026-31229 🟠 Łataj w tym tygodniu

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., mod…

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-12
CVE-2026-31237 🟠 Łataj w tym tygodniu

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines …

9.8 CVSS
0.4% EPSS
deserializationrce 2026-05-12
CVE-2026-73397 🟠 Łataj w tym tygodniu

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

9.8 CVSS
0.4% EPSS
deserialization 2026-08-18
CVE-2025-39480 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer allows Object Injection.This issue affects Car Dealer: from n/a before 1.6.8.

9.8 CVSS
0.4% EPSS
deserialization 2025-05-23
CVE-2026-7858 🟠 Łataj w tym tygodniu

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Rele…

9.8 CVSS
0.3% EPSS
deserializationrce 2026-06-01
CVE-2024-24797 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.

9.8 CVSS
0.3% EPSS
CVE-2026-15976 🟠 Łataj w tym tygodniu

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickl…

9.8 CVSS
0.3% EPSS
CVE-2024-48033 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.

9.8 CVSS
0.3% EPSS
deserialization 2024-10-11
CVE-2025-32897 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. Th…

9.8 CVSS
0.3% EPSS
CVE-2025-56422 🟠 Łataj w tym tygodniu

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

9.8 CVSS
0.2% EPSS
CVE-2026-34084 🔴 Łataj teraz

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument …

9.8 CVSS
0.2% EPSS
CVE-2026-40044 🟠 Łataj w tym tygodniu

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to…

9.8 CVSS
0.2% EPSS
deserialization 2026-04-13
CVE-2024-47552 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Severity Justification: The Apache Seata security team asses…

9.8 CVSS
0.1% EPSS
CVE-2014-125112 🟠 Łataj w tym tygodniu

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execut…

9.8 CVSS
0.1% EPSS
CVE-2025-49380 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7…

9.8 CVSS
0.1% EPSS
deserialization 2025-10-22
CVE-2026-4851 🟠 Łataj w tym tygodniu

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to exe…

9.8 CVSS
0.1% EPSS
CVE-2025-59007 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a throu…

9.8 CVSS
0.1% EPSS
deserialization 2025-10-22
CVE-2026-31235 🟠 Łataj w tym tygodniu

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to deserialize data received via a m…

9.8 CVSS
0.1% EPSS
deserialization 2026-05-12
CVE-2026-31238 🟠 Łataj w tym tygodniu

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files usin…

9.8 CVSS
0.1% EPSS
deserializationrce 2026-05-12
CVE-2026-22500 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-22507 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24378 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-24989 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25029 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25030 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25031 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25032 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25429 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27082 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27083 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27084 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-27095 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat …

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32502 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-32512 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.

9.8 CVSS
0.1% EPSS
deserialization 2026-03-25
CVE-2026-25449 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Shinetheme Traveler allows Object Injection.This issue affects Traveler: from n/a before 3.2.8.1.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-18
CVE-2025-60233 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2025-60237 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

9.8 CVSS
0.0% EPSS
deserialization 2026-03-19
CVE-2026-42472 🟠 Łataj w tym tygodniu

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.

9.8 CVSS
0.0% EPSS
deserialization 2026-05-01
CVE-2026-42473 🟠 Łataj w tym tygodniu

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.

9.8 CVSS
0.0% EPSS
deserialization 2026-05-01
CVE-2026-31239 🟠 Łataj w tym tygodniu

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to l…

9.8 CVSS
0.0% EPSS
deserialization 2026-05-12
CVE-2023-51414 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.

9.6 CVSS
0.6% EPSS
CVE-2026-34659 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker cou…

9.6 CVSS
0.6% EPSS
CVE-2022-3861 🟠 Łataj w tym tygodniu

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import…

8.8 CVSS
4.6% EPSS
CVE-2022-2434 🟡 Monitoruj

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users…

8.8 CVSS
4.2% EPSS
CVE-2023-51545 🟠 Łataj w tym tygodniu

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and recruitments.This issue affects Job Manager & Career – Manage job boar…

9.6 CVSS
0.2% EPSS
CVE-2023-52200 🟠 Łataj w tym tygodniu

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARM…

9.6 CVSS
0.2% EPSS
CVE-2026-34615 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.3 CVSS
1.6% EPSS
CVE-2024-49271 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimi…

9.1 CVSS
1.9% EPSS
CVE-2024-48042 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.

9.1 CVSS
1.9% EPSS
deserializationrce 2024-10-16
CVE-2022-2444 🟡 Monitoruj

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, and including 3.7.9. This makes it possi…

8.8 CVSS
2.7% EPSS
CVE-2022-23307 🟡 Monitoruj
appsos

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

8.8 CVSS
2.7% EPSS
CVE-2024-52434 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

9.1 CVSS
1.0% EPSS
CVE-2026-14890 🟠 Łataj w tym tygodniu

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a mali…

9.1 CVSS
0.9% EPSS
CVE-2026-27962 🔴 Łataj teraz

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrar…

9.1 CVSS
0.5% EPSS
CVE-2026-71560 🟠 Łataj w tym tygodniu
apps

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payl…

9.1 CVSS
0.5% EPSS
CVE-2023-52205 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.

9.1 CVSS
0.5% EPSS
CVE-2023-52202 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.

9.1 CVSS
0.5% EPSS
CVE-2026-64609 🟠 Łataj w tym tygodniu
apps

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization i…

9.1 CVSS
0.5% EPSS
CVE-2016-3415 🟠 Łataj w tym tygodniu

Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.

9.1 CVSS
0.5% EPSS
CVE-2023-52207 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.

9.1 CVSS
0.5% EPSS
CVE-2026-25923 🔴 Łataj teraz

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attacke…

9.1 CVSS
0.4% EPSS
CVE-2023-49777 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

9.1 CVSS
0.4% EPSS
CVE-2024-43252 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

9.0 CVSS
0.8% EPSS
deserialization 2024-08-19
CVE-2026-65665 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
1.7% EPSS
CVE-2026-12046 🟠 Łataj w tym tygodniu

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module m…

9.0 CVSS
0.7% EPSS
CVE-2026-25769 🔴 Łataj teraz

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All …

9.1 CVSS
0.2% EPSS
CVE-2026-50076 🟠 Łataj w tym tygodniu
apps

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedLi…

9.1 CVSS
0.2% EPSS
CVE-2026-66805 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
1.6% EPSS
CVE-2026-66808 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
1.6% EPSS
CVE-2026-5426 🟠 Łataj w tym tygodniu

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via …

9.1 CVSS
0.1% EPSS
deserializationrce 2026-04-16
CVE-2024-43242 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

9.0 CVSS
0.6% EPSS
CVE-2024-50408 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.

8.8 CVSS
1.5% EPSS
CVE-2023-43176 🟠 Łataj w tym tygodniu

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

8.8 CVSS
1.5% EPSS
CVE-2026-70426 🟠 Łataj w tym tygodniu

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path …

9.0 CVSS
0.3% EPSS
deserialization 2026-08-05
CVE-2026-9319 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

9.0 CVSS
0.2% EPSS
CVE-2026-63639 🟡 Monitoruj

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers…

8.8 CVSS
1.2% EPSS
deserializationrce 2026-08-18
CVE-2024-30227 🟠 Łataj w tym tygodniu

Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.

9.0 CVSS
0.2% EPSS
deserialization 2024-03-28
CVE-2024-1872 🟡 Monitoruj

The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted input in the button_shortcode function. This makes it possible for authe…

8.8 CVSS
1.2% EPSS
deserialization 2024-03-29
CVE-2026-65658 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
1.1% EPSS
CVE-2026-65663 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

8.8 CVSS
1.1% EPSS
CVE-2022-2436 🟡 Monitoruj

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attack…

8.8 CVSS
1.1% EPSS
CVE-2026-45484 🟡 Monitoruj
appscloud

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

8.8 CVSS
1.0% EPSS
CVE-2025-33244 🟠 Łataj w tym tygodniu

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A success…

9.0 CVSS
0.0% EPSS
deserializationdos 2026-03-24
CVE-2026-44795 🟡 Monitoruj

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or Cl…

8.8 CVSS
1.0% EPSS
CVE-2024-50416 🟡 Monitoruj

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through …

8.8 CVSS
0.9% EPSS