CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 1 of 70
- CVE-2026-20131CRITICALCVSS 10.0EG 10.0⚠ KEV2026-03-04
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vuln…
- CVE-2025-55182CRITICALCVSS 10.0EG 10.0⚠ KEV2025-12-03
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-…
- CVE-2023-40044CRITICALCVSS 10.0EG 10.0⚠ KEV2023-09-27
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
- CVE-2021-44228CRITICALCVSS 10.0EG 10.0⚠ KEV2021-12-10
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoin…
- CVE-2025-10035CRITICALCVSS 9.8EG 10.0⚠ KEV2025-09-18
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- CVE-2025-5086CRITICALCVSS 9.0EG 10.0⚠ KEV2025-06-02
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
- CVE-2025-49113CRITICALCVSS 9.9EG 9.9⚠ KEV2025-06-02
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
- CVE-2025-24016CRITICALCVSS 9.9EG 9.9⚠ KEV2025-02-10
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. …
- CVE-2026-63077CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-27
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVE-2026-58644CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-50522CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-12569CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-18
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS …
- CVE-2026-45247CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-26
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the C…
- CVE-2025-40551CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-28
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited wi…
- CVE-2026-20963CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2025-59287CRITICALCVSS 9.8EG 9.8⚠ KEV2025-10-14
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
- CVE-2025-26399CRITICALCVSS 9.8EG 9.8⚠ KEV2025-09-23
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is…
- CVE-2025-53770CRITICALCVSS 9.8EG 9.8⚠ KEV2025-07-20
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing a…
- CVE-2025-24813CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-10
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache…
- CVE-2025-23006CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-23
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote u…
- CVE-2024-40711CRITICALCVSS 9.8EG 9.8⚠ KEV2024-09-07
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- CVE-2024-28986CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-13
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticat…
- CVE-2023-46604CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-27
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipul…
- CVE-2023-43208CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-26
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
- CVE-2023-38203CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-20
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does…
- CVE-2023-29300CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-12
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this i…
- CVE-2023-26359CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-23
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Expl…
- CVE-2022-47986CRITICALCVSS 9.8EG 9.8⚠ KEV2023-02-17
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit thi…
- CVE-2022-31199CRITICALCVSS 9.8EG 9.8⚠ KEV2022-11-08
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist…
- CVE-2022-35405CRITICALCVSS 9.8EG 9.8⚠ KEV2022-07-19
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
- CVE-2022-21445CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-19
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows u…
- CVE-2021-23758CRITICALCVSS 9.8EG 9.8⚠ KEV2021-12-03
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
- CVE-2021-42237CRITICALCVSS 9.8EG 9.8⚠ KEV2021-11-05
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required…
- CVE-2021-35464CRITICALCVSS 9.8EG 9.8⚠ KEV2021-07-22
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single c…
- CVE-2021-27852CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-27
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
- CVE-2020-7961CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-20
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
- CVE-2020-10189CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-06
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
- CVE-2020-2555CRITICALCVSS 9.8EG 9.8⚠ KEV2020-01-15
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability…
- CVE-2019-18935CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-11
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017…
- CVE-2019-0344CRITICALCVSS 9.8EG 9.8⚠ KEV2019-08-14
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Inje…
- CVE-2019-9874CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-31
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET obje…
- CVE-2019-10068CRITICALCVSS 9.8EG 9.8⚠ KEV2019-03-26
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service…
- CVE-2018-1000861CRITICALCVSS 9.8EG 9.8⚠ KEV2018-12-10
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on …
- CVE-2018-4939CRITICALCVSS 9.8EG 9.8⚠ KEV2018-05-19
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2018-2628CRITICALCVSS 9.8EG 9.8⚠ KEV2018-04-19
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability all…
- CVE-2018-0147CRITICALCVSS 9.8EG 9.8⚠ KEV2018-03-08
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is…
- CVE-2017-1000353CRITICALCVSS 9.8EG 9.8⚠ KEV2018-01-29
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedO…
- CVE-2017-12149CRITICALCVSS 9.8EG 9.8⚠ KEV2017-10-04
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization …
- CVE-2017-3066CRITICALCVSS 9.8EG 9.8⚠ KEV2017-04-27
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary c…
- CVE-2015-7450CRITICALCVSS 9.8EG 9.8⚠ KEV2016-01-02
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →