51 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-70416 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica | CRITICAL | 10.0 | 58%ile | NVD | 2026-09-16 |
| CVE-2026-87719 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 | CRITICAL | 9.9 | 48%ile | NVD | 2026-09-12 |
| CVE-2026-82845 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deser | CRITICAL | 9.9 | 29%ile | NVD | 2026-09-12 |
| CVE-2026-20307 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to exec | CRITICAL | 9.9 | 60%ile | NVD | 2026-09-16 |
| CVE-2026-78006 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including | CRITICAL | 9.8 | 54%ile | NVD | 2026-09-12 |
| CVE-2026-62379 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice P | CRITICAL | 9.8 | 50%ile | NVD | 2026-09-15 |
| CVE-2025-59953 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior | CRITICAL | 9.8 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-20242 | A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could | CRITICAL | 9.8 | 49%ile | NVD | 2026-09-16 |
| CVE-2025-66455 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior | CRITICAL | 9.8 | — | NVD | 2026-09-18 |
| CVE-2026-81657 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system | CRITICAL | 9.8 | — | NVD | 2026-09-18 |
| CVE-2026-82340 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled refl | CRITICAL | 9.8 | — | NVD | 2026-09-18 |
| CVE-2026-54752 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The vali | CRITICAL | 9.6 | 29%ile | NVD | 2026-09-17 |
| CVE-2026-90919 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_reg | CRITICAL | 9.3 | 62%ile | NVD | 2026-09-14 |
| CVE-2026-67399 | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute | CRITICAL | 9.3 | 51%ile | NVD | 2026-09-14 |
| CVE-2023-54398 | Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageS | CRITICAL | 9.3 | 49%ile | NVD | 2026-09-15 |
| CVE-2026-91939 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing | CRITICAL | 9.3 | 47%ile | NVD | 2026-09-15 |
| CVE-2026-93467 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execu | CRITICAL | 9.3 | 43%ile | NVD | 2026-09-18 |
| CVE-2026-45051 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serial | CRITICAL | 9.2 | 42%ile | NVD | 2026-09-15 |
| CVE-2026-62263 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize ap | CRITICAL | 9.2 | 45%ile | NVD | 2026-09-15 |
| CVE-2026-46495 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/ | CRITICAL | 9.2 | 53%ile | NVD | 2026-09-15 |
| CVE-2026-92785 | Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist val | CRITICAL | 9.2 | 30%ile | NVD | 2026-09-16 |
| CVE-2026-76834 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array obje | CRITICAL | 9.2 | 56%ile | NVD | 2026-09-17 |
| CVE-2026-20211 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlyi | CRITICAL | 9.1 | 45%ile | NVD | 2026-09-16 |
| CVE-2026-20341 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenti | CRITICAL | 9.1 | 38%ile | NVD | 2026-09-16 |
| CVE-2026-78175 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all v | HIGH | 8.8 | 47%ile | NVD | 2026-09-12 |
| CVE-2026-61701 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until | HIGH | 8.8 | 43%ile | NVD | 2026-09-14 |
| CVE-2026-13293 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.8 | 46%ile | NVD | 2026-09-14 |
| CVE-2026-12728 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.8 | 49%ile | NVD | 2026-09-15 |
| CVE-2026-20340 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands | HIGH | 8.8 | 52%ile | NVD | 2026-09-16 |
| CVE-2026-54916 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abse | HIGH | 8.8 | 35%ile | NVD | 2026-09-17 |
| CVE-2026-17086 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object I | HIGH | 8.8 | 58%ile | NVD | 2026-09-18 |
| CVE-2026-72649 | Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution | HIGH | 8.8 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-63639 | Valkey: UAF in stream deserialization may lead to remote code execution | HIGH | 8.8 | 58%ile | Microsoft | 2026-08-11 |
| CVE-2026-90777 | ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitr | HIGH | 8.7 | 42%ile | NVD | 2026-09-13 |
| CVE-2026-11729 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.5 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-84099 | The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that | HIGH | 8.1 | 19%ile | NVD | 2026-09-12 |
| CVE-2026-28364 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re | HIGH | 7.9 | 12%ile | Microsoft | 2026-02-10 |
| CVE-2026-17156 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-17416 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-45794 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS c | HIGH | 7.7 | 43%ile | NVD | 2026-09-15 |
| CVE-2026-62997 | Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.P | HIGH | 7.7 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-93872 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comment | HIGH | 7.7 | — | NVD | 2026-09-18 |
| CVE-2026-10751 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati | HIGH | 7.5 | — | NVD | 2026-09-18 |
| CVE-2026-90472 | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively de | MEDIUM | 6.9 | 27%ile | NVD | 2026-09-12 |
| CVE-2026-11711 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service componen | MEDIUM | 6.5 | — | NVD | 2026-09-18 |
| CVE-2026-88976 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0. | MEDIUM | 6.1 | 17%ile | NVD | 2026-09-16 |
| CVE-2026-90614 | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_mode | MEDIUM | 5.3 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-49400 | October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, th | LOW | 3.3 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-90575 | A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login | LOW | 2.9 | 39%ile | NVD | 2026-09-13 |
| CVE-2026-90490 | A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the compone | LOW | 2.1 | 33%ile | NVD | 2026-09-13 |
| CVE-2026-91842 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert o | LOW | 1.2 | 30%ile | NVD | 2026-09-15 |