Vulnerabilities (CVE)

Filtered by CWE-502
Total 3246 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65658 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65665 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65663 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2017-12149 1 Redhat 1 Jboss Enterprise Application Platform 2026-08-13 7.5 HIGH 9.8 CRITICAL
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
CVE-2026-65576 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65579 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-65571 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
CVE-2026-65574 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
CVE-2026-65549 2026-08-12 N/A 7.2 HIGH
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-65578 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-28139 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-65573 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65577 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65552 2026-08-12 N/A 9.8 CRITICAL
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVE-2026-65572 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-65575 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-65556 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
CVE-2026-65581 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-35502 2026-08-12 N/A N/A
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
CVE-2026-63516 1 Microsoft 1 Sharepoint Server 2026-08-12 N/A 6.5 MEDIUM
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.