CVE-2026-24165
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerabi
CVSS
7.8
Alto
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 31 mar 2026 · Última mod.: 24 jul 2026 · CWE-502
0.3%EPSS · 30 días0.3%
2026-08-142026-09-10
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-621078.8 ALT—
———Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.9hCVE-2026-621059.8 CRÍ—
———Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.9hCVE-2026-621039.8 CRÍ—
———Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.9hCVE-2026-736997.2 ALT—
——0FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.1dCVE-2026-817848.1 ALT—
——0Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.1dCVE-2026-829258.1 ALT21.2%
——6The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such installs. The Site Reviews WordPress plugin before 8.3.0's own code contains no chain onward from the injected object, so how far it reaches depends on the other code present on the site.2d