Search Results (3399 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103877 1 Apache 1 Directory Ldap Api 2026-10-02 8.1 High
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.  This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.
CVE-2026-12544 2 Redhat, Theforeman 4 Satellite, Satellite Capsule, Satellite Utils and 1 more 2026-10-02 7.7 High
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
CVE-2026-94390 2 Dotstore, Wordpress-extensions 2 Hide Shipping Method For Woocommerce, Hide Shipping Method For Woocommerce 2026-10-01 7.2 High
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
CVE-2026-97256 2 Greg–siteorigin, Wordpress-extensions 2 Page Builder By Siteorigin, Page Builder By Siteorigin 2026-10-01 7.2 High
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
CVE-2026-97291 2 Magazine3, Wordpress-extensions 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp 2026-10-01 8.8 High
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-100512 2 Hook & Filter, Wordpress-extensions 2 Nested Pages, Nested Pages 2026-10-01 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-102377 2 10web, Wordpress-extensions 2 Photo Gallery, Photo Gallery By 10web 2026-10-01 8.8 High
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-102392 2 Themehigh, Wordpress-extensions 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce 2026-10-01 7.2 High
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
CVE-2026-103441 1 Wikimedia 1 Mediawiki-wikibase Extension 2026-10-01 N/A
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.
CVE-2026-55083 1 Dhis2 1 Dhis2-core 2026-10-01 9.1 Critical
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
CVE-2026-43642 1 Softaculous 1 Virtualizor 2026-10-01 8.1 High
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserialization by setting the act parameter to login with the from_billing_module parameter present. Attackers can pass malicious serialized data through the billing_data POST field to the unserialize() function without allowed_classes restrictions, enabling exploitation of available POP chains to achieve remote code execution as root.
CVE-2026-12256 2 Theme-fusion, Wordpress 2 Avada, Wordpress 2026-10-01 8.8 High
Deserialization of Untrusted Data vulnerability in ThemeFusion Fusion Builder fusion-builder allows Object Injection.This issue affects Fusion Builder: from n/a through 3.15.3.
CVE-2026-58163 2 Apache, Apache Software Foundation 2 Traffic Server, Apache Traffic Server 2026-10-01 7.5 High
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-97284 2026-10-01 8.8 High
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
CVE-2026-102135 1 Kiteworks 1 Kiteworks Email Protection Gateway 2026-10-01 6.6 Medium
On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.
CVE-2026-102108 1 Kiteworks 1 Kiteworks Email Protection Gateway 2026-10-01 7.2 High
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
CVE-2026-73699 1 Filerun 1 Filerun 2026-10-01 7.2 High
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.
CVE-2026-102101 1 Kiteworks 1 Core 2026-10-01 8.1 High
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.
CVE-2026-103395 1 Modeltc 1 Lightllm 2026-10-01 9.8 Critical
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
CVE-2026-35502 1 Intel 2 Extension For Pytorch, Intel Extension For Pytorch 2026-09-30 5.3 Medium
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.