Total
3240 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19116 | 2026-09-03 | N/A | 8.8 HIGH | ||
| The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site. | |||||
| CVE-2023-3360 | 2026-09-03 | N/A | 3.3 LOW | ||
| The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog. | |||||
| CVE-2026-84670 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |||||
| CVE-2026-84647 | 2026-09-03 | N/A | 8.8 HIGH | ||
| In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended. | |||||
| CVE-2026-83497 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint. | |||||
| CVE-2026-3245 | 2026-09-03 | N/A | 7.5 HIGH | ||
| A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | |||||
| CVE-2026-81772 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |||||
| CVE-2025-13805 | 2026-09-03 | 2.6 LOW | 3.7 LOW | ||
| A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component LiteRpc-Serializer. Executing a manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-68756 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 6.6 MEDIUM |
| A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | |||||
| CVE-2026-59285 | 1 Vmware | 1 Spring For Graphql | 2026-09-02 | N/A | 8.1 HIGH |
| Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 | |||||
| CVE-2026-72649 | 1 Elastic | 1 Elasticsearch | 2026-09-02 | N/A | 8.8 HIGH |
| Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models. | |||||
| CVE-2026-16138 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-09-02 | N/A | 8.0 HIGH |
| In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. | |||||
| CVE-2026-25551 | 2026-09-02 | N/A | 7.8 HIGH | ||
| Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, limiting the attack surface to local access only. The endpoint is configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full. A low-privileged local attacker can send YSoSerial.NET-generated BinaryFormatter payloads to the localhost-bound endpoint to achieve code execution as NT AUTHORITY\\\\SYSTEM. The vulnerability was corrected in BarTender 12.1, released on August 14, 2026. Users should upgrade to BarTender 12.1 or later. | |||||
| CVE-2026-47864 | 1 Vmware | 1 Spring Integration | 2026-09-02 | N/A | 6.4 MEDIUM |
| SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via readObject(). If an application using this converter on an inbound HTTP endpoint has any known Java deserialization "gadget" on its classpath, a remote, unauthenticated attacker can achieve arbitrary code execution. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier | |||||
| CVE-2026-47875 | 1 Broadcom | 1 Spring Batch | 2026-09-02 | N/A | 5.6 MEDIUM |
| Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 | |||||
| CVE-2026-81283 | 2026-09-02 | N/A | 8.8 HIGH | ||
| Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |||||
| CVE-2026-61760 | 1 Nvidia | 1 Nemo Megatron Bridge | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |||||
| CVE-2026-61761 | 1 Nvidia | 1 Nemo Megatron Bridge | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |||||
| CVE-2026-61762 | 1 Nvidia | 1 Nemo Megatron Bridge | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |||||
| CVE-2026-61763 | 1 Nvidia | 1 Nemo Megatron Bridge | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |||||
