CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 11 of 70
- CVE-2025-40553CRITICALCVSS 9.8EG 9.82026-01-28
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited wi…
- CVE-2026-0773CRITICALCVSS 9.8EG 9.82026-01-23
Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Upsonic. Authentication is not required to exploit…
- CVE-2026-0764CRITICALCVSS 9.8EG 9.82026-01-23
GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to ex…
- CVE-2026-0763CRITICALCVSS 9.8EG 9.82026-01-23
GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authenticati…
- CVE-2026-0760CRITICALCVSS 9.8EG 9.82026-01-23
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGP…
- CVE-2025-69079CRITICALCVSS 9.8EG 9.82026-01-22
Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9.
- CVE-2025-67617CRITICALCVSS 9.8EG 9.82026-01-22
Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.
- CVE-2026-24009CRITICALCVSS 9.8EG 9.82026-01-22
Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in d…
- CVE-2026-23524CRITICALCVSS 9.8EG 9.82026-01-21
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHP’s unserialize() function without restricting which cla…
- CVE-2025-56005CRITICALCVSS 9.8EG 9.82026-01-20
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle…
- CVE-2023-7334CRITICALCVSS 9.8EG 9.82026-01-15
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind.…
- CVE-2025-67911CRITICALCVSS 9.8EG 9.82026-01-08
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
- CVE-2025-47552CRITICALCVSS 9.8EG 9.82026-01-07
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.
- CVE-2025-64233CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.
- CVE-2025-64227CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
- CVE-2025-64206CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.
- CVE-2025-60180CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.
- CVE-2025-60178CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a through <= 1.2.6.
- CVE-2025-60174CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.2.
- CVE-2025-60091CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9.
- CVE-2025-60090CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6.
- CVE-2025-60089CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.
- CVE-2025-54723CRITICALCVSS 9.8EG 9.82025-12-18
Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a through < 1.4.3.
- CVE-2025-65213CRITICALCVSS 9.8EG 9.82025-12-15
MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_single_op() and nan_inf_track_for_single_op() functions use pickle.load() on user-controlled fi…
- CVE-2025-34394CRITICALCVSS 9.8EG 9.82025-12-10
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code executio…
- CVE-2025-66631CRITICALCVSS 9.8EG 9.82025-12-09
CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is…
- CVE-2025-51746CRITICALCVSS 9.8EG 9.82025-11-25
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.
- CVE-2025-51745CRITICALCVSS 9.8EG 9.82025-11-25
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.
- CVE-2025-51744CRITICALCVSS 9.8EG 9.82025-11-25
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.
- CVE-2025-51743CRITICALCVSS 9.8EG 9.82025-11-25
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.
- CVE-2025-51742CRITICALCVSS 9.8EG 9.82025-11-25
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead t…
- CVE-2025-61168CRITICALCVSS 9.8EG 9.82025-11-25
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
- CVE-2025-59245CRITICALCVSS 9.8EG 9.82025-11-20
Microsoft SharePoint Online Elevation of Privilege Vulnerability
- CVE-2025-11367CRITICALCVSS 9.8EG 9.82025-11-12
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
- CVE-2025-60245CRITICALCVSS 9.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.
- CVE-2025-58998CRITICALCVSS 9.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701.
- CVE-2025-58636CRITICALCVSS 9.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.3.
- CVE-2025-53242CRITICALCVSS 9.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1.
- CVE-2025-49393CRITICALCVSS 9.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.2.
- CVE-2025-64164CRITICALCVSS 9.8EG 9.82025-11-06
Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Int…
- CVE-2025-12305CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. The manipulation results in deserializatio…
- CVE-2025-62025CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8.
- CVE-2025-60238CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a through <= 9.04.02.
- CVE-2025-60232CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5.
- CVE-2025-60226CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This issue affects White Rabbit: from n/a through <= 1.5.2.
- CVE-2025-60225CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a through <= 1.5.0.
- CVE-2025-60224CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object Injection.This issue affects Subscribe to Download: from n/a through <= 2.0.9.
- CVE-2025-60221CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injection.This issue affects Captivate Sync: from n/a through <= 3.0.3.
- CVE-2025-60216CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects Addison: from n/a through < 1.4.8.
- CVE-2025-60214CRITICALCVSS 9.8EG 9.82025-10-22
Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/a through < 1.3.0.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →