Vulnerabilities (CVE)

Filtered by CWE-502
Total 3246 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-40733 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
CVE-2026-39576 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
CVE-2026-39556 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
CVE-2026-39442 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
CVE-2025-69111 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
CVE-2025-60236 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
CVE-2025-60231 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
CVE-2025-60229 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
CVE-2025-60205 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
CVE-2025-69108 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
CVE-2025-69122 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
CVE-2026-12256 2026-06-17 N/A 8.8 HIGH
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
CVE-2026-40759 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
CVE-2026-39539 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
CVE-2026-40760 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
CVE-2026-27429 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
CVE-2026-49075 2026-06-17 N/A 9.8 CRITICAL
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
CVE-2026-39577 2026-06-17 N/A 5.5 MEDIUM
Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
CVE-2026-40758 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
CVE-2026-40736 2026-06-17 N/A 8.1 HIGH
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.