PULSE
LIVE50signals / 24h
FEED
ransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Servicesransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Services
← All CVEs
CVE WatchJul 23, 2026

CVE-2026-59544

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

CVSS

9.8

Critical

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-502

EPSS · 30d

Not enough EPSS history yet.

Technical description

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654977.2 HIG
0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.4h
CVE-2026-654937.5 HIG
0Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.4h
CVE-2026-167239.0 CRI
47.9%
14A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.7h
CVE-2026-131908.1 HIG
46.1%
14In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.20h
CVE-2026-131858.1 HIG
46.1%
14In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.20h
CVE-2026-242324.3 MED
3.8%
1NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.2d