Total
3237 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-71374 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18. | |||||
| CVE-2026-19795 | 2026-09-08 | N/A | 6.2 MEDIUM | ||
| Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input. | |||||
| CVE-2026-10196 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1. | |||||
| CVE-2025-61140 | 1 Dchester | 1 Jsonpath | 2026-09-07 | N/A | 9.8 CRITICAL |
| The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. | |||||
| CVE-2026-84834 | 2026-09-07 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | |||||
| CVE-2026-84753 | 2026-09-05 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |||||
| CVE-2026-47856 | 1 Vmware | 1 Spring Integration | 2026-09-04 | N/A | 6.3 MEDIUM |
| Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier | |||||
| CVE-2026-59306 | 1 Vmware | 1 Spring Cloud Stream | 2026-09-04 | N/A | 3.1 LOW |
| Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |||||
| CVE-2026-84832 | 2026-09-04 | N/A | N/A | ||
| SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |||||
| CVE-2026-61484 | 1 Apache | 1 Lucy | 2026-09-04 | N/A | 9.8 CRITICAL |
| ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at https://github.com/lucysearch . 0.8.0 is no longer affected by this issue, because the offending feature has been removed there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-34993 | 1 Aiohttp | 1 Aiohttp | 2026-09-04 | N/A | 6.4 MEDIUM |
| AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading. | |||||
| CVE-2026-84752 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | |||||
| CVE-2026-19116 | 2026-09-03 | N/A | 8.8 HIGH | ||
| The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site. | |||||
| CVE-2023-3360 | 2026-09-03 | N/A | 3.3 LOW | ||
| The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog. | |||||
| CVE-2026-84670 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |||||
| CVE-2026-84647 | 2026-09-03 | N/A | 8.8 HIGH | ||
| In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended. | |||||
| CVE-2026-83497 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint. | |||||
| CVE-2026-3245 | 2026-09-03 | N/A | 7.5 HIGH | ||
| A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | |||||
| CVE-2026-81772 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |||||
| CVE-2025-13805 | 2026-09-03 | 2.6 LOW | 3.7 LOW | ||
| A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component LiteRpc-Serializer. Executing a manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been made available to the public and could be used for attacks. | |||||
