Export limit exceeded: 386826 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3244 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28139 | 2 Wordpress, Wp-dreams | 2 Wordpress, Ajax Search | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||||
| CVE-2026-16258 | 2026-08-07 | 9.8 Critical | ||
| The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution. | ||||
| CVE-2026-65575 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | ||||
| CVE-2026-65581 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | ||||
| CVE-2026-65579 | 2 Axiomthemes, Wordpress | 2 Agricola, Wordpress | 2026-08-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | ||||
| CVE-2026-21655 | 3 Johnson Control, Johnson Controls, Johnsoncontrols | 4 Victor, Ccure 9000, Victor Application Server and 1 more | 2026-08-06 | N/A |
| Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. | ||||
| CVE-2026-70430 | 1 Jenkins Project | 1 Jenkins | 2026-08-06 | 2.7 Low |
| Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators. | ||||
| CVE-2026-65573 | 2 Themerex, Wordpress | 2 Abelle, Wordpress | 2026-08-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | ||||
| CVE-2026-65577 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||||
| CVE-2026-65552 | 2 Qlstudio, Wordpress | 2 Export User Data, Wordpress | 2026-08-06 | 9.8 Critical |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | ||||
| CVE-2026-65549 | 2026-08-06 | 7.2 High | ||
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | ||||
| CVE-2026-65576 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | ||||
| CVE-2026-65574 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | ||||
| CVE-2026-65578 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | ||||
| CVE-2026-69098 | 1 Cinnamon | 1 Kotaemon | 2026-08-05 | 9.8 Critical |
| kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges. | ||||
| CVE-2026-50646 | 2 Microsoft, Redhat | 19 .net, .net Framework, Microsoft Visual Studio 2022 and 16 more | 2026-08-05 | 7.8 High |
| Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-47623 | 2 Linux, Nvidia | 2 Linux Kernel, Dynamo | 2026-08-05 | 8.2 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-50649 | 2 Microsoft, Redhat | 19 .net, .net Framework, Microsoft Visual Studio 2022 and 16 more | 2026-08-05 | 7.8 High |
| Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-60372 | 1 Oracle | 1 Platform Security For Java | 2026-08-05 | 9.8 Critical |
| Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-16062 | 2026-08-04 | 6.6 Medium | ||
| The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories. | ||||
