Vulnerabilities (CVE)

Filtered by CWE-502
Total 2987 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48287 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Injection.This issue affects Pix 4x sem juros - Pagaleve: from n/a through <= 1.6.9.
CVE-2025-48200 2026-06-17 N/A 10.0 CRITICAL
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.
CVE-2025-48134 1 Shapedplugin 1 Wp Tabs 2026-06-17 N/A 7.2 HIGH
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.This issue affects WP Tabs: from n/a through <= 2.2.12.
CVE-2025-48101 2026-06-17 N/A 8.8 HIGH
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.
CVE-2025-48086 2026-06-17 N/A 5.5 MEDIUM
Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3.
CVE-2025-48018 2026-06-17 N/A 7.5 HIGH
An authenticated user can modify application state data.
CVE-2025-47994 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 7.8 HIGH
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47784 1 Emlog 1 Emlog 2026-06-17 N/A 9.8 CRITICAL
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return `false`. Commit 9643250802188b791419e3c2188577073256a8a2 fixes the issue.
CVE-2025-47771 2026-06-17 N/A N/A
PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in the read method of the SparseMatrix class that can lead to a wide range of privilege escalations depending on the circumstances. This method takes in an InputStream and returns a SparseMatrix object. This issue has been patched in com.powsybl:powsybl-math: 6.7.2. A workaround for this issue involves not using SparseMatrix deserialization (SparseMatrix.read(...) methods).
CVE-2025-47732 1 Microsoft 1 Dataverse 2026-06-17 N/A 8.7 HIGH
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
CVE-2025-47683 2026-06-17 N/A 7.2 HIGH
Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Injection.This issue affects WP Maintenance: from n/a through <= 6.1.9.7.
CVE-2025-47660 2026-06-17 N/A 8.8 HIGH
Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.
CVE-2025-47629 1 Wp-crm 1 Wp-crm System 2026-06-17 N/A 7.2 HIGH
Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Object Injection.This issue affects WP-CRM System: from n/a through <= 3.4.5.
CVE-2025-47584 1 Themegoods 1 Photography 2026-06-17 N/A 8.5 HIGH
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.
CVE-2025-47582 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.
CVE-2025-47581 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0.
CVE-2025-47579 1 Themegoods 1 Photography 2026-06-17 N/A 9.0 CRITICAL
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.
CVE-2025-47568 1 Digitalzoomstudio 1 Zoomsounds 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91.
CVE-2025-47553 2026-06-17 N/A 8.8 HIGH
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25.
CVE-2025-47552 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.