CVE-2026-59544
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-502
Sin historial EPSS suficiente todavía.
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-654977.2 ALT—
——0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.3hCVE-2026-654937.5 ALT—
——0Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.3hCVE-2026-167239.0 CRÍ47.9%
——14A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.6hCVE-2026-131908.1 ALT46.1%
——14In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.19hCVE-2026-131858.1 ALT46.1%
——14In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.19hCVE-2026-242324.3 MED3.8%
——1NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.2d