Search Results (3496 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93929 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.
CVE-2026-93927 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
CVE-2026-62130 2026-10-11 7.2 High
Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
CVE-2026-62046 2 Themerex Group, Wordpress-extensions 2 Gutentype, Gutentype 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
CVE-2026-62045 2 Themerex Group, Wordpress-extensions 2 Booklovers, Booklovers 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
CVE-2026-62044 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
CVE-2026-62021 2026-10-11 8.8 High
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
CVE-2026-42719 2026-10-11 9.8 Critical
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
CVE-2026-106606 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a through 3.31.0.
CVE-2026-105885 2026-10-11 8.8 High
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
CVE-2026-105872 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-for-woocommerce allows Object Injection.This issue affects Product Configurator for WooCommerce: from n/a through 1.7.5.
CVE-2026-104398 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.
CVE-2026-100730 1 Grid Protection Alliance 2 Openhistorian, Openpdc 2026-10-11 9.8 Critical
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
CVE-2026-81797 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
CVE-2026-78535 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
CVE-2026-78533 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
CVE-2026-78531 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
CVE-2026-78529 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
CVE-2026-66569 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
CVE-2026-66568 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.