Search Results (2618 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-4851 1 Casiano 2 Grid::machine, Grid\ 2026-04-02 9.8 Critical
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to execute code on them. A compromised or malicious remote host can execute arbitrary code back on the client through unsafe deserialization in the RPC protocol. read_operation() in lib/GRID/Machine/Message.pm deserialises values from the remote side using eval() $arg .= '$VAR1'; my $val = eval "no strict; $arg"; # line 40-41 $arg is raw bytes from the protocol pipe. A compromised remote host can embed arbitrary perl in the Dumper-formatted response: $VAR1 = do { system("..."); }; This executes on the client silently on every RPC call, as the return values remain correct. This functionality is by design but the trust requirement for the remote host is not documented in the distribution.
CVE-2026-20963 1 Microsoft 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 2026-04-02 9.8 Critical
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2025-49073 2 Axiomthemes, Wordpress 2 Sweet Dessert, Wordpress 2026-04-01 N/A
Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: from n/a through < 1.1.13.
CVE-2025-48134 1 Shapedplugin 1 Wp Tabs 2026-04-01 7.2 High
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.This issue affects WP Tabs: from n/a through <= 2.2.12.
CVE-2025-47629 1 Wp-crm 1 Wp-crm System 2026-04-01 7.2 High
Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Object Injection.This issue affects WP-CRM System: from n/a through <= 3.4.5.
CVE-2025-47579 2 Themegoods, Wordpress 2 Photography, Wordpress 2026-04-01 8.1 High
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.
CVE-2025-47568 2 Digitalzoomstudio, Zoomit 2 Zoomsounds, Zoomsounds 2026-04-01 N/A
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91.
CVE-2025-39565 1 Melapress 1 Melapress Login Security 2026-04-01 7.2 High
Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue affects MelaPress Login Security: from n/a through <= 2.1.0.
CVE-2025-39485 1 Themegoods 1 Grand Tour 2026-04-01 N/A
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5.6.
CVE-2025-39354 2 Themegoods, Wordpress 2 Grand Conference, Wordpress 2026-04-01 N/A
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.This issue affects Grand Conference: from n/a through <= 5.3.
CVE-2025-39349 1 Potenzaglobalsolutions 1 Ciyashop 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop ciyashop allows Object Injection.This issue affects CiyaShop: from n/a through <= 4.18.0.
CVE-2025-39348 1 Themegoods 1 Grand Restaurant 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.
CVE-2025-32928 1 Themegoods 1 Altair 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects Altair: from n/a through <= 5.2.2.
CVE-2025-32927 1 Chimpgroup 1 Foodbakery 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This issue affects FoodBakery: from n/a through <= 3.3.
CVE-2025-31084 1 Sunshinephotocart 1 Sunshine Photo Cart 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10.
CVE-2025-26967 1 Wpgeodirectory 1 Events Calendar* 2026-04-01 8.8 High
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14.
CVE-2025-22777 1 Givewp 1 Givewp 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.
CVE-2024-54367 1 Ultimatemember 1 Forumwp 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0.
CVE-2024-52433 1 Mindstien 1 My Geo Posts Free 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.
CVE-2024-52432 2 Nix Solutions, Nixsolutions 2 Nix Anti-spam Light, Nix Anti-spam Light 2026-04-01 9.8 Critical
Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.