Export limit exceeded: 404313 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (3496 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97291 2 Magazine3, Wordpress-extensions 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp 2026-10-01 8.8 High
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-100512 2 Hook & Filter, Wordpress-extensions 2 Nested Pages, Nested Pages 2026-10-01 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-102377 2 10web, Wordpress-extensions 2 Photo Gallery, Photo Gallery By 10web 2026-10-01 8.8 High
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-102392 2 Themehigh, Wordpress-extensions 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce 2026-10-01 7.2 High
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
CVE-2026-103441 1 Wikimedia 1 Mediawiki-wikibase Extension 2026-10-01 N/A
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.
CVE-2026-55083 1 Dhis2 1 Dhis2-core 2026-10-01 9.1 Critical
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
CVE-2026-43642 1 Softaculous 1 Virtualizor 2026-10-01 8.1 High
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserialization by setting the act parameter to login with the from_billing_module parameter present. Attackers can pass malicious serialized data through the billing_data POST field to the unserialize() function without allowed_classes restrictions, enabling exploitation of available POP chains to achieve remote code execution as root.
CVE-2026-12256 2 Theme-fusion, Wordpress 2 Avada, Wordpress 2026-10-01 8.8 High
Deserialization of Untrusted Data vulnerability in ThemeFusion Fusion Builder fusion-builder allows Object Injection.This issue affects Fusion Builder: from n/a through 3.15.3.
CVE-2026-58163 2 Apache, Apache Software Foundation 2 Traffic Server, Apache Traffic Server 2026-10-01 7.5 High
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-97284 2026-10-01 8.8 High
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
CVE-2026-73699 1 Filerun 1 Filerun 2026-10-01 7.2 High
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.
CVE-2026-103395 1 Modeltc 1 Lightllm 2026-10-01 9.8 Critical
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
CVE-2026-35502 1 Intel 2 Extension For Pytorch, Intel Extension For Pytorch 2026-09-30 5.3 Medium
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
CVE-2026-101169 1 Octopus 1 Octopus Server 2026-09-30 N/A
In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.
CVE-2026-100841 1 Project-monai 1 Monai 2026-09-30 7.8 High
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC scratch, ~/.cache/monai) can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache, resulting in arbitrary code execution in that user's context. All released versions of the monai pip package are affected; no patched version is available as of the advisory.
CVE-2026-80428 1 Ilias 1 Ilias 2026-09-30 9.8 Critical
ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user.
CVE-2026-102455 1 Digiwin 1 Easyflow .net 2026-09-30 9.8 Critical
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
CVE-2026-100843 1 Project-monai 1 Monai 2026-09-30 7.8 High
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.
CVE-2026-100308 1 Aws 1 Gluonts 2026-09-30 7.8 High
Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. To remediate this issue, users should upgrade to version 0.17.0 or later.
CVE-2026-97248 2026-09-30 9.8 Critical
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.