Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 555— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
mylittleforum Phar Deserialization Arbitrary File Deletion (CVE-2026-25923)
github.com · 2026-02-10

From this webpage screenshot, the following key vulnerability information can be obtained: 1. **Vulnerability Overview**: - **Vulnerability Title**: Phar Deserialization leading to Arbitrary File Dele…

Read more
python-diskcache CVE-2025-69872 Unsafe Pickle Deserialization Advisory
github.com · 2026-02-12

```md ### Key Information #### CVE-2025-69872: DiskCache Unsafe Pickle Deserialization - **CVE ID**: CVE-2025-69872 - **Vendor**: python-diskcache project - **Product**: DiskCache (python-diskcache) -…

Read more
zyddnys/manga-image-translator Unsafe Pickle Deserialization RCE
github.com · 2026-02-12

### Key Information #### Vulnerability Description - **Type**: RCE (Remote Code Execution) due to insecure Pickle deserialization - **Affected Project**: zyddnys/manga-image-translator - **Affected En…

Read more
Infoblox NIOS High-Severity Vulnerabilities: Arbitrary File Write (CVE-2025-61879) and Insecure Deserialization RCE (CVE
support.infoblox.com · 2026-02-13

- **Vulnerability Details** - **CVEs:** CVE-2025-61879, CVE-2025-61880 - **Affected Versions:** - NIOS - Version 8.5.2 - NIOS - Version 8.6.x - NIOS - Version 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6 …

Read more
CVSS 5.3
Custom Registration Form Builder: Potential Deserialization and RCE in PayPal Service
plugins.trac.wordpress.org · 2026-02-21

- **Plugin Name**: Custom Registration Form Builder with Submission Manager - **File Path**: `/custom-registration-form-builder-with-submission-manager/tags/6.0.6.7/services/class_rm_paypal_service.ph…

Read more
Premium intel
CVSS 7.8
NVIDIA NeMo Framework CVE-2025-33253 Deserialization Vulnerability
nvd.nist.gov · 2026-02-21

### Key Information #### Description - **CVE ID:** CVE-2025-33253 - **Description:** The NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincin…

Read more
Premium intel
CVSS 7.5
openITCOCKPIT 5.3.1 Unsafe PHP Deserialization in Gearman Worker (CVE-2026-24891)
github.com · 2026-02-21

### Critical Vulnerability Information #### Vulnerability Overview - **Vulnerability Name**: Unsafe PHP Deserialization in Gearman Worker Allows Conditional Object Injection - **Risk Level**: High - *…

Read more
CVE-2026-26220: Unauthenticated RCE via Pickle Deserialization in LightLLM
github.com · 2026-02-21

# CVE-2026-26220: Unauthenticated RCE via Pickle Deserialization in PD WebSocket Endpoints ## Summary - **CVE**: CVE-2026-26220 - **CVSS 4.0**: 9.3 Critical (AV:N/AC:L/AT:N/PR:N/UI:N/N:VC:H/VI:H/VA:H/…

Read more
Premium intel
CVSS 7.8
CVE-2026-26208: ADB Explorer Insecure Deserialization RCE
github.com · 2026-02-21

### Vulnerability Key Information #### Vulnerability Overview - **Vulnerability Type**: Insecure Deserialization leading to Remote Code Execution (RCE) - **Source**: ADB Explorer - **Vulnerability ID*…

Read more
Boltz Insecure Deserialization RCE (CVE-2025-70560)
github.com · 2026-02-21

### Key Information - **Vulnerability Title** - Boltz contains an insecure deserialization vulnerability in its molecule loading functionality - **CVE ID** - CVE-2025-70560 - **GHSA ID** - GHSA-fjm6-8…

Read more
CVSS 5.5
FunAdmin v7.1.0-rc4 Unsafe Deserialization Leading to Arbitrary File Write
github.com · 2026-02-22

### Critical Vulnerability Information - **Product Information** - Product Name: FunAdmin - PHP Version: 8.2.9 - FunAdmin Version: v7.1.0-rc4 - Product Link: [https://gitee.com/funadmin/funadmin](http…

Read more
CVSS 5.5
FunAdmin v7.1.0-rc4 Insecure Deserialization Leads to Arbitrary File Write
github.com · 2026-02-22

## Vulnerability Key Information ### Product Information - Product: [https://gitee.com/funadmin/funadmin](https://gitee.com/funadmin/funadmin) - PHP Version: 8.2.9 - FunAdmin Version: v7.1.0-rc4 ### V…

Read more
CVSS 4.6
datapizza-ai v0.0.7 Unsafe Deserialization in Redis Cache via pickle.loads()
github.com · 2026-02-23

### Key Information Summary - **Vulnerability Type**: Unsafe Deserialization - **Affected Component**: `pickle.loads()` in `datapizza-ai Redis cache` - **CVSS Score**: 7.9 (High) - Base Score 3.1 (per…

Read more
CVSS 4.6
datapizza-ai Redis Cache Unsafe Deserialization RCE via pickle.loads()
github.com · 2026-02-23

### Summary - **Vulnerability:** Unsafe Deserialization via pickle.loads() in datapizza-ai Redis cache. - **Impact:** Allows Remote Command Execution on the server host. - **CVSSv3:** HIGH 7.9/10 - **…

Read more
CVSS 4.6
datapizza-ai 0.0.2 Deserialization Vulnerability (CVE-2026-2970)
vuldb.com · 2026-02-23

- **Vulnerability Description**: A critical vulnerability in `datapizza-labs datapizza-ai 0.0.2`, affecting the `RedisCache` function in `cache/redis/cache.py`. Data deserialization issue can occur wi…

Read more
Apache Camel camel-leveldb Deserialization RCE (CVE-2026-25747) Analysis and Exploitation
github.com · 2026-02-23

### Vulnerability Key Information Summary #### 1. Vulnerability Overview - **CVE ID**: CVE-2026-25747 - **Component**: camel-leveldb - **Affected Class**: DefaultLevelDBSerializer.java - **Vulnerable …

Read more
Premium intel
CVSS 8.9
mchange-commons-java JNDI Deserialization RCE Vulnerability (CVE-2026-27727)
github.com · 2026-02-26

## Critical Vulnerability Information ### Vulnerability Description - **Title**: mchange-commons-java prior to v0.4.0 can be dangerously abused to download and execute malicious code - **Publisher**: …

Read more
Premium intel
CVSS 6.6
LangGraph BaseCache Deserialization RCE (CVE-2026-27794)
github.com · 2026-02-26

The following key information about the vulnerability can be obtained from the screenshot: ```markdown ## Vulnerability Overview - **Vulnerability Identifier**: ZDI-CAN-28385 - **Vulnerability Descrip…

Read more
CVSS 7.2
WooCommerce Custom Product Tabs Lite 1.9.1 Update: Potential SQLi and Deserialization Risks
plugins.trac.wordpress.org · 2026-02-26

### Key Information #### Changeset - **ID**: 3226839 - **Timestamp**: 01/22/2025 12:34:55 PM - **Author**: SkyVerge - **Message**: Committing 1.9.1 to trunk - **Location**: woocommerce-custom-product-…

Read more
CVSS 8.9
CVE-2026-27830: c3p0 Java Deserialization RCE Vulnerability
github.com · 2026-02-26

### Critical Vulnerability Information #### Overview - **Title**: c3p0 prior to v0.12.0 can be dangerously abused to download and execute malicious code - **Publisher**: swaldman - **CVE ID**: CVE-202…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.