Total
2980 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-4266 | 2026-06-17 | N/A | N/A | ||
| An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.This issue affects Fireware OS: 12.1 through 12.11.8 and 2025.1 through 2026.1.2. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T-15 and T-35. | |||||
| CVE-2026-49781 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. | |||||
| CVE-2026-49770 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | |||||
| CVE-2026-49769 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | |||||
| CVE-2026-49768 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | |||||
| CVE-2026-49765 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |||||
| CVE-2026-49109 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. | |||||
| CVE-2026-49106 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | |||||
| CVE-2026-49105 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | |||||
| CVE-2026-49104 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. | |||||
| CVE-2026-49085 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | |||||
| CVE-2026-48919 | 1 Jenkins | 1 Active Directory | 2026-06-17 | N/A | 6.6 MEDIUM |
| Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | |||||
| CVE-2026-48917 | 1 Jenkins | 1 Ldap | 2026-06-17 | N/A | 6.6 MEDIUM |
| Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. | |||||
| CVE-2026-48853 | 2026-06-17 | N/A | N/A | ||
| Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process. This issue affects grpc from 0.4.0 before 1.0.0. | |||||
| CVE-2026-47161 | 2026-06-17 | N/A | N/A | ||
| RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker can execute arbitrary commands on the host server. Combined with missing network isolation in the code execution sandbox, this allows an authenticated student to achieve full Remote Code Execution (RCE) on the host system. Commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb fixes the issue. | |||||
| CVE-2026-46725 | 2026-06-17 | N/A | N/A | ||
| The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with "Persistent Mode: Static" in the plugin settings. | |||||
| CVE-2026-45134 | 2026-06-17 | N/A | 7.1 HIGH | ||
| LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest content is controlled by an external party, but prior versions of the SDK did not distinguish this from pulling a prompt within the caller's own organization. This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0. | |||||
| CVE-2026-44501 | 1 Datahub | 1 Datahub | 2026-06-17 | N/A | 4.3 MEDIUM |
| DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data vulnerability (CWE-502) affecting the GET /callback/oidc endpoint. Successful exploitation requires a valid user account in the configured OIDC identity provider This vulnerability is fixed in 1.5.0.3. | |||||
| CVE-2026-44126 | 2026-06-17 | N/A | N/A | ||
| SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object. | |||||
| CVE-2026-42779 | 1 Apache | 1 Mina | 2026-06-17 | N/A | 9.8 CRITICAL |
| The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class filter before calling Class.forName(). Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6. The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade. | |||||
