Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 561— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 9.8
RCE Vulnerability in loophole-mvc BaseKontrol Dynamic Class Loading
github.com · 2026-08-18

### Vulnerability Overview The webpage screenshot displays a file named `BaseKontrol.java`, which belongs to the `loophole-mvc` project. A potential security vulnerability exists within this file: spe…

Read more
Premium intel
CVSS 8.8
Dell Command | Update Vulnerabilities: RCE, Auth Bypass, Deserialization CVEs
www.dell.com · 2026-08-19

### Vulnerability Overview - **Vulnerability ID**: DSA-2026-309 - **Vulnerability Type**: Multiple security vulnerabilities in Dell Command | Update - **Release Date**: August 18, 2026 - **CVSS Score*…

Read more
Premium intel
CVSS 8.2
Wazuh v4.10.4 Security Update: Path Traversal & Deserialization Fixes
github.com · 2026-08-20

### Vulnerability Overview In Wazuh v4.10.4, several security vulnerabilities and fixes have been addressed, primarily concerning plugin decoder parameter alignment, path traversal, cluster deserializ…

Read more
Premium intel
CVSS 8.4
Wazuh Cluster DAPI Protocol Deserialization Leading to RCE
github.com · 2026-08-20

### Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability #### Vulnerability Overview This vulnerability exists in the `merge()` function of `framework/wazu…

Read more
Premium intel
CVSS 9.8
ImDeploy disagg Pickle Deserialization RCE Vulnerability and Fix
github.com · 2026-08-20

### Vulnerability Overview This vulnerability involves the use of `pickle` for data serialization in P2P ZMQ requests, rather than JSON. Since `pickle` can execute arbitrary code, an attacker can craf…

Read more
Premium intel
CVSS 9.8
Unauthenticated ZMQ Pickle Deserialization RCE in IntellLM Imdeploy
github.com · 2026-08-20

### Vulnerability Overview **Title**: [Bug] Unauthenticated pickle deserialization via ZMQ in disaggregated serving → RCE #4804 **Description**: - **Vulnerability Type**: Unauthenticated pickle deseri…

Read more
fabric-sdk-java Deserialization Vulnerability Analysis and POC
xz.aliyun.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: Mining Deserialization Exploitation Chain in fabric-sdk-java - **Discovery Method**: The vulnerability was identified by searching for `readObject`…

Read more
CVE-2026-31235 | Notion
www.notion.so · 2026-05-22

# CVE-2026-31235 Vulnerability Summary ## Vulnerability Overview - **Vulnerability Name**: Pickle Deserialization Vulnerability - **Affected Component**: `BackgroundAugmenter` class in the `imgaug` li…

Read more
Comments.php in classified-listing/trunk/app/Controllers/Hooks – WordPress Plugin Repository
plugins.trac.wordpress.org · 2026-05-22

# Vulnerability Summary ## Overview This webpage screenshot displays the source code file `Comments.php` for a WordPress plugin named `classified-listing`. The code contains multiple potential securit…

Read more
CraftCMS Commerce RCE via SQLi and PHP Deserialization (CVE-2026-52271)
github.com · 2026-04-18

# Vulnerability Summary: craftcms/commerce Remote Code Execution Vulnerability ## Overview This vulnerability exists in the TotalRevenue widget of `craftcms/commerce`. An attacker can leverage an SQL …

Read more
www.wordfence.com · 2026-05-03

# Vulnerability Summary ## Vulnerability Overview * **Vulnerability Name**: Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2023-46604) * **Vulnerability Type**: Remote Code Execution (RCE) *…

Read more
www.wordfence.com · 2026-05-05

# Vulnerability Summary ## Vulnerability Overview * **Vulnerability Name**: Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2023-46604) * **Vulnerability Type**: Remote Code Execution (RCE) *…

Read more
CVSS 7.5
Apache ActiveMQ CVE-2023-46604 RCE via STOMP Deserialization with POC
www.wordfence.com · 2026-05-24

# Vulnerability Overview **Vulnerability Name**: Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2023-46604) **Vulnerability Description**: Apache ActiveMQ is an open-source message broker an…

Read more
CVSS 5.3
jackson-databind @JsonIgnore annotation bypass vulnerability fix and POC analysis
github.com · 2026-06-27

### Vulnerability Overview This vulnerability involves bypassing setter methods annotated with `@JsonIgnore` during deserialization via private fields. Specifically, when a property name is included i…

Read more
NepCTF 2026 JavaMix 题目 SSRF 与反序列化 RASP 绕过分析-先知社区
xz.aliyun.com · 2026-07-25

### Vulnerability Overview - **Vulnerability Name**: Analysis of SSRF and Deserialization RASP Bypass - **Vulnerability Type**: SSRF (Server-Side Request Forgery) and Deserialization Vulnerabilities -…

Read more
【AI安全】模型文件攻击面:从 Pickle 反序列化到 GGUF 模板注入-先知社区
xz.aliyun.com · 2026-07-26

### Vulnerability Overview - **Vulnerability Name**: Attack Surface of Model Files: From Pickle Deserialization to GGUF Template Injection - **Vulnerability Types**: Pickle Deserialization Vulnerabili…

Read more
www.wordfence.com · 2026-05-05

# Vulnerability Summary ## Vulnerability Overview * **Vulnerability Name**: Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2023-46604) * **Vulnerability Type**: Remote Code Execution (RCE) *…

Read more
Unsafe deserialization in file-backed session manager leads to RCE (CVE-2026-7818) · Issue #9901 · pgadmin-org/pgadmin4
github.com · 2026-05-22

# Vulnerability Summary: Insecure Deserialization in pgAdmin4 File Backup Session Manager Leads to Remote Code Execution (CVE-2026-7818) ## Vulnerability Overview An insecure deserialization vulnerabi…

Read more
Jenkins Security Bulletin: RCE, XSS, Auth Bypass & Multiple CVEs (2026-06-10)
www.jenkins.io · 2026-06-13

### Jenkins Security Advisory 2026-06-10 #### Vulnerability Overview 1. **Deserialization Vulnerability** - **Security ID**: SECURITY-3707 / CVE-2026-53435 - **Severity**: High - **Description**: Jenk…

Read more
Podatność w oprogramowaniu Quick.CMS | CERT Polska
cert.pl · 2026-06-15

# Vulnerability Overview - **Vulnerability Name**: CVE-2026-1189 - **Vulnerability Type**: Deserialization of Untrusted Data - **Vulnerability Description**: Quick CMS deserializes user-controlled dat…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.