Deserialization Vulnerabilities

10 advisories classified as Deserialization

10

Total CVEs

8

Critical

2

High

CVE-2026-42472

May 1, 2026

Critical (9.8)

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object....

Read Advisory

CVE-2026-42473

May 1, 2026

Critical (9.8)

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object....

Read Advisory

CVE-2026-33819

Apr 23, 2026

Critical (10.0)

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network....

Read Advisory

CVE-2026-40044

Apr 13, 2026

Critical (9.8)

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PH...

Read Advisory

CVE-2026-5536

Apr 5, 2026

High (7.3)

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deseria...

Read Advisory

CVE-2026-27962

Mar 16, 2026

Critical (9.1)

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attack...

Read Advisory

CVE-2026-27685

Mar 10, 2026

Critical (9.1)

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentialit...

Read Advisory

CVE-2026-2599

Mar 5, 2026

Critical (9.8)

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input ...

Read Advisory

CVE-2026-2471

Feb 28, 2026

High (7.5)

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. Thi...

Read Advisory

CVE-2026-23542

Feb 19, 2026

Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10....

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.