Total
2960 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-61168 | 1 Sigb | 1 Pmb | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file. | |||||
| CVE-2025-60889 | 1 Stellar-group | 1 Hpx | 2026-07-05 | N/A | 9.8 CRITICAL |
| Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts. | |||||
| CVE-2025-25691 | 1 Prestashop | 1 Prestashop | 2026-07-05 | N/A | 6.5 MEDIUM |
| A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. | |||||
| CVE-2025-60887 | 2026-07-05 | N/A | 5.3 MEDIUM | ||
| An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, where Cista does not perform sufficient checks to safeguard against self-referencing pointers and referencing other data within the payload. The leak occurs if the deserialized values are observable by the attacker. | |||||
| CVE-2025-56422 | 1 Limesurvey | 1 Limesurvey | 2026-07-05 | N/A | 9.8 CRITICAL |
| A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. | |||||
| CVE-2025-25692 | 1 Prestashop | 1 Prestashop | 2026-07-05 | N/A | 6.5 MEDIUM |
| A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. | |||||
| CVE-2024-44902 | 1 Thinkphp | 1 Thinkphp | 2026-07-05 | N/A | 9.8 CRITICAL |
| A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | |||||
| CVE-2026-13759 | 1 Ibm | 1 Websphere Extreme Scale | 2026-07-03 | N/A | 7.5 HIGH |
| IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs | |||||
| CVE-2026-7871 | 1 Langflow | 1 Langflow | 2026-07-02 | N/A | 9.8 CRITICAL |
| IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity. | |||||
| CVE-2026-55223 | 2026-07-02 | N/A | N/A | ||
| c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them as "properties" assumed safe while they actually call into JDBC drivers. Attackers can thus craft malicious DataSource objects whose property lookups invoke vulnerable drivers, then smuggle them in serialized form to where an application deserializes and auto-resolves bean properties — triggering the attack. This requires a susceptible DataSource/ConnectionPoolDataSource and JDBC driver on the CLASSPATH, plus a carrier that auto-looks-up JavaBean properties on = deserialization, most commonly a collection paired with an Apache commons-beanutils Comparator that sorts by bean properties. c3p0 supplied that susceptible DataSource/ConnectionPoolDataSource, which was an essential component of the trigger. This issue has been fixed in version 0.14.0. | |||||
| CVE-2026-51947 | 2026-07-02 | N/A | 9.8 CRITICAL | ||
| An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this issue exists because of an incomplete fix for CVE-2026-39253. | |||||
| CVE-2026-56037 | 2026-07-02 | N/A | 8.8 HIGH | ||
| Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3. | |||||
| CVE-2026-27414 | 2026-07-02 | N/A | 8.8 HIGH | ||
| Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. | |||||
| CVE-2026-24250 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-24244 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-24251 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-24247 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-24245 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-24243 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-24240 | 2 Linux, Nvidia | 2 Linux Kernel, Nemo Megatron Bridge | 2026-07-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
