Total
2419 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-68899 | 2026-01-27 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4.
|
|||||
| CVE-2025-68903 | 2026-01-27 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0.
|
|||||
| CVE-2026-24656 | 1 Apache | 1 Karaf Decanter | 2026-01-27 | N/A | 3.7 LOW |
|
Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.
The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.
It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.
NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this is ...
Show More |
|||||
| CVE-2025-69079 | 2026-01-27 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9.
|
|||||
| CVE-2025-50004 | 2026-01-27 | N/A | 8.5 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.
|
|||||
| CVE-2026-24815 | 2026-01-27 | N/A | N/A | ||
|
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java.
This issue affects tis: before v4.3.0.
|
|||||
| CVE-2026-0895 | 2026-01-26 | N/A | N/A | ||
|
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension. More information about this vulnerability can be found in the related ...
Show More |
|||||
| CVE-2026-0726 | 2026-01-26 | N/A | 8.1 HIGH | ||
|
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a P ...
Show More |
|||||
| CVE-2026-23524 | 2026-01-26 | N/A | 9.8 CRITICAL | ||
|
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHP’s unserialize() function without restricting which classes can be instantiated, which leaves users vulnerable to Remote Code Execution. The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication, but only affects Laravel Reverb when horizontal scaling is ...
Show More |
|||||
| CVE-2026-24009 | 2026-01-26 | N/A | 8.1 HIGH | ||
|
Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in docling-core starting in version 2.21.0 and prior to version 2.48.4, specifically only if the application uses pyyaml prior to version 5.4 and invokes `docling_core.types.doc.DoclingDocument.load_from_yaml()` passing it untrusted YAML data. The vulnerability has ...
Show More |
|||||
| CVE-2026-0773 | 2026-01-26 | N/A | 9.8 CRITICAL | ||
|
Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Upsonic. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the add_tool endpoint, which listens on TCP port 7541 by default. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacke ...
Show More |
|||||
| CVE-2025-30025 | 1 Axis | 2 Camera Station Pro, Device Manager | 2026-01-23 | N/A | 7.8 HIGH |
|
The communication protocol used between the
server process and the service control had a flaw that could lead to a local privilege escalation.
|
|||||
| CVE-2025-30023 | 1 Axis | 3 Camera Station, Camera Station Pro, Device Manager | 2026-01-23 | N/A | 9.0 CRITICAL |
|
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
|
|||||
| CVE-2023-7334 | 1 Chanjetvip | 1 T\+ | 2026-01-23 | N/A | 9.8 CRITICAL |
|
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitr ...
Show More |
|||||
| CVE-2024-30226 | 1 Wpdeveloper | 1 Betterdocs | 2026-01-23 | N/A | 9.0 CRITICAL |
|
Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.
|
|||||
| CVE-2025-11346 | 1 Ilias | 1 Ilias | 2026-01-23 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 is able to mitigate this issue. It is advisable to upgrade the affected component.
|
|||||
| CVE-2025-11345 | 1 Ilias | 1 Ilias | 2026-01-23 | 6.5 MEDIUM | 5.5 MEDIUM |
|
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve this issue. Upgrading the affected component is advised.
|
|||||
| CVE-2025-47584 | 1 Themegoods | 1 Photography | 2026-01-22 | N/A | 8.5 HIGH |
|
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.
|
|||||
| CVE-2025-47579 | 1 Themegoods | 1 Photography | 2026-01-22 | N/A | 9.0 CRITICAL |
|
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography. This issue affects Photography: from n/a through 7.5.2.
|
|||||
| CVE-2025-14071 | 2026-01-22 | N/A | 7.5 HIGH | ||
|
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin, which means this vulnerability has no impact unless another plugin or theme containing a PO ...
Show More |
|||||
| CVE-2025-14930 | 1 Huggingface | 1 Transformers | 2026-01-21 | N/A | 7.8 HIGH |
|
Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of weights. The issue results from the lack of proper validation of user-supplied data, which ca ...
Show More |
|||||
| CVE-2025-14920 | 1 Huggingface | 1 Transformers | 2026-01-21 | N/A | 7.8 HIGH |
|
Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied ...
Show More |
|||||
| CVE-2025-14921 | 1 Huggingface | 1 Transformers | 2026-01-21 | N/A | 7.8 HIGH |
|
Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-sup ...
Show More |
|||||
| CVE-2025-14929 | 1 Huggingface | 1 Transformers | 2026-01-21 | N/A | 7.8 HIGH |
|
Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of ...
Show More |
|||||
| CVE-2025-5499 | 1 Phpwcms | 1 Phpwcms | 2026-01-20 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation of the argument imgfile leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.
|
|||||
| CVE-2025-5498 | 1 Phpwcms | 1 Phpwcms | 2026-01-20 | 6.5 MEDIUM | 5.5 MEDIUM |
|
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. The manipulation of the argument cpage_custom leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is r ...
Show More |
|||||
| CVE-2025-68038 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through <= 5.9.11.
|
|||||
| CVE-2025-67911 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
|
|||||
| CVE-2025-67535 | 2026-01-20 | N/A | 6.5 MEDIUM | ||
|
Deserialization of Untrusted Data vulnerability in WePlugins - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.
|
|||||
| CVE-2025-66073 | 2026-01-20 | N/A | 6.5 MEDIUM | ||
|
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.
|
|||||
| CVE-2025-66055 | 2026-01-20 | N/A | 7.2 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.
|
|||||
| CVE-2025-64353 | 2026-01-20 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.
|
|||||
| CVE-2025-64266 | 2026-01-20 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4.
|
|||||
| CVE-2025-64233 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.
|
|||||
| CVE-2025-64227 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
|
|||||
| CVE-2025-64206 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.
|
|||||
| CVE-2025-62035 | 2026-01-20 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
|
|||||
| CVE-2025-62025 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8.
|
|||||
| CVE-2025-62008 | 2026-01-20 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Table For WooCommerce: from n/a through <= 1.2.4.
|
|||||
| CVE-2025-60245 | 2026-01-20 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.
|
|||||