Total
2419 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-23946 | 1 Tendenci | 1 Tendenci | 2026-02-17 | N/A | 6.8 MEDIUM |
|
Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a critical deserialization vulnerability in the Helpdesk module (which is not enabled by default). This vulnerability allows Remote Code Execution (RCE) by an authenticated user with staff security level due to using Python's pickle module in helpdesk /reports/. The original CVE-2020-14942 was incompletely patched. While ticket_list() was fixed to use ...
Show More |
|||||
| CVE-2026-23685 | 1 Sap | 1 Netweaver | 2026-02-17 | N/A | 4.4 MEDIUM |
|
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.
|
|||||
| CVE-2026-26208 | 2026-02-13 | N/A | 7.8 HIGH | ||
|
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to supply a crafted JSON file containing a gadget chain (e.g., ObjectDataProvider) to execute arbitrary code when the application launches and subsequently saves its settings. This vulnera ...
Show More |
|||||
| CVE-2026-26221 | 2026-02-13 | N/A | N/A | ||
|
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other ...
Show More |
|||||
| CVE-2026-25614 | 1 Phillipsdata | 1 Blesta | 2026-02-13 | N/A | 7.5 HIGH |
|
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
|
|||||
| CVE-2026-25615 | 1 Phillipsdata | 1 Blesta | 2026-02-13 | N/A | 7.2 HIGH |
|
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
|
|||||
| CVE-2025-47732 | 1 Microsoft | 1 Dataverse | 2026-02-13 | N/A | 8.7 HIGH |
|
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
|
|||||
| CVE-2025-34153 | 2026-02-13 | N/A | N/A | ||
|
Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031 with the URI endpoint TimerServer, implemented in Hyland.Core.Timers.dll. This endpoint deserializes untrusted input using the .NET BinaryFormatter, allowing attackers to execute arbitrary code under the context of NT AUTHORITY\SYSTEM.
|
|||||
| CVE-2026-23864 | 1 Facebook | 1 React | 2026-02-13 | N/A | 7.5 HIGH |
|
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.
The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code.
Strongly co ...
Show More |
|||||
| CVE-2026-21531 | 1 Microsoft | 1 Azure Conversation Authoring Client Library | 2026-02-12 | N/A | 9.8 CRITICAL |
|
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
|
|||||
| CVE-2026-26215 | 2026-02-12 | N/A | N/A | ||
|
manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled request bodies using pickle.loads() without validation. Although a nonce-based authorization check is intended to restrict access, the nonce defaults to an empty string and the check is skipped, allowing remote attackers to e ...
Show More |
|||||
| CVE-2026-21511 | 1 Microsoft | 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more | 2026-02-11 | N/A | 7.5 HIGH |
|
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-70559 | 2026-02-11 | N/A | 6.5 MEDIUM | ||
|
pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.
|
|||||
| CVE-2026-1235 | 2026-02-11 | N/A | 6.5 MEDIUM | ||
|
The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
|
|||||
| CVE-2026-0910 | 2026-02-11 | N/A | 8.8 HIGH | ||
|
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the si ...
Show More |
|||||
| CVE-2025-10492 | 1 Cloud | 5 Jasperreports Io, Jasperreports Library, Jasperreports Server and 2 more | 2026-02-10 | N/A | 9.8 CRITICAL |
|
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
|
|||||
| CVE-2026-25923 | 2026-02-10 | N/A | N/A | ||
|
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature, trigger Phar deserialization through BBCode [img] tag processing, and exploit Smarty 4.1.0 POP chain to achieve arbitrary file deletion. This vulnerability is fixed in 20260208.1.
|
|||||
| CVE-2026-25632 | 2026-02-06 | N/A | 10.0 CRITICAL | ||
|
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subp ...
Show More |
|||||
| CVE-2025-56005 | 1 Dabeaz | 1 Ply | 2026-02-06 | N/A | 9.8 CRITICAL |
|
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code via `__reduce__()`, an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet ...
Show More |
|||||
| CVE-2026-21226 | 1 Microsoft | 1 Azure Core Shared Client Library | 2026-02-05 | N/A | 7.5 HIGH |
|
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
|
|||||
| CVE-2025-63617 | 1 Kutangguo | 1 Ktg-mes | 2026-02-05 | N/A | 6.5 MEDIUM |
|
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.
|
|||||
| CVE-2020-37071 | 2026-02-04 | N/A | 9.8 CRITICAL | ||
|
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.
|
|||||
| CVE-2025-48780 | 1 Scshr | 1 Hr Portal | 2026-02-04 | N/A | 9.8 CRITICAL |
|
A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.
|
|||||
| CVE-2025-40551 | 1 Solarwinds | 1 Web Help Desk | 2026-02-03 | N/A | 9.8 CRITICAL |
|
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
|
|||||
| CVE-2026-24954 | 2026-02-03 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.
|
|||||
| CVE-2025-30160 | 1 Redlib | 1 Redlib | 2026-02-03 | N/A | 7.5 HIGH |
|
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
|
|||||
| CVE-2025-33210 | 1 Nvidia | 1 Isaac Lab | 2026-02-02 | N/A | 9.0 CRITICAL |
|
NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.
|
|||||
| CVE-2026-24747 | 1 Linuxfoundation | 1 Pytorch | 2026-01-30 | N/A | 8.8 HIGH |
|
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.
|
|||||
| CVE-2025-27925 | 1 Nintex | 1 Automation | 2026-01-29 | N/A | 8.5 HIGH |
|
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
|
|||||
| CVE-2025-67619 | 2026-01-29 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n/a through <= 3.2.
|
|||||
| CVE-2025-67617 | 2026-01-29 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.
|
|||||
| CVE-2025-69099 | 2026-01-28 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects North: from n/a through <= 5.7.5.
|
|||||
| CVE-2025-27522 | 1 Apache | 1 Inlong | 2026-01-28 | N/A | 6.5 MEDIUM |
|
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1]
https://github.com/apache/inlong/pull/11732
|
|||||
| CVE-2024-37502 | 1 Wpwebelite | 1 Woocommerce Social Login | 2026-01-28 | N/A | 5.4 MEDIUM |
|
Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login.This issue affects WooCommerce Social Login: from n/a through 2.6.3.
|
|||||
| CVE-2025-68047 | 2026-01-28 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.1.
|
|||||
| CVE-2025-69036 | 2026-01-28 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n/a through <= 16.4.
|
|||||
| CVE-2025-69035 | 2026-01-28 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental Care CPT: from n/a through <= 20.2.
|
|||||
| CVE-2025-69002 | 2026-01-28 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9.
|
|||||
| CVE-2025-39485 | 1 Themegoods | 1 Grand Tour | 2026-01-28 | N/A | 9.8 CRITICAL |
|
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.
|
|||||
| CVE-2025-39354 | 1 Themegoods | 1 Grand Conference | 2026-01-28 | N/A | 9.8 CRITICAL |
|
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference allows Object Injection.This issue affects Grand Conference: from n/a through 5.2.
|
|||||