CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 2 of 70
- CVE-2015-4852CRITICALCVSS 9.8EG 9.8⚠ KEV2015-11-18
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to …
- CVE-2025-42999CRITICALCVSS 9.1EG 9.1⚠ KEV2025-05-13
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability…
- CVE-2025-53690CRITICALCVSS 9.0EG 9.0⚠ KEV2025-09-03
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
- CVE-2026-45659CRITICALCVSS 8.8EG 9.0⚠ KEV2026-05-26
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-0994CRITICALCVSS 8.8EG 9.0⚠ KEV2025-02-06
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack agai…
- CVE-2024-20953CRITICALCVSS 8.8EG 9.0⚠ KEV2024-02-17
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to co…
- CVE-2023-21529CRITICALCVSS 8.8EG 9.0⚠ KEV2023-02-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2020-0688CRITICALCVSS 8.8EG 9.0⚠ KEV2020-02-11
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- CVE-2020-0618CRITICALCVSS 8.8EG 9.0⚠ KEV2020-02-11
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
- CVE-2019-15271CRITICALCVSS 8.8EG 9.0⚠ KEV2019-11-26
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid…
- CVE-2019-9875CRITICALCVSS 8.8EG 9.0⚠ KEV2019-05-31
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
- CVE-2018-0824CRITICALCVSS 8.8EG 9.0⚠ KEV2018-05-09
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 20…
- CVE-2021-39144CRITICALCVSS 8.5EG 9.0⚠ KEV2021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stre…
- CVE-2024-4978CRITICALCVSS 8.4EG 9.0⚠ KEV2024-05-23
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized Po…
- CVE-2020-17144CRITICALCVSS 8.4EG 9.0⚠ KEV2020-12-10
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2025-3935CRITICALCVSS 8.1EG 9.0⚠ KEV2025-04-25
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It …
- CVE-2019-6340CRITICALCVSS 8.1EG 9.0⚠ KEV2019-02-21
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the f…
- CVE-2018-15133CRITICALCVSS 8.1EG 9.0⚠ KEV2018-08-09
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Enc…
- CVE-2017-9805CRITICALCVSS 8.1EG 9.0⚠ KEV2017-09-15
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when dese…
- CVE-2024-8069CRITICALCVSS 8.0EG 9.0⚠ KEV2024-11-12
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
- CVE-2022-41082CRITICALCVSS 8.0EG 9.0⚠ KEV2022-10-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2025-8875CRITICALCVSS 7.8EG 9.0⚠ KEV2025-08-14
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
- CVE-2021-26857CRITICALCVSS 7.8EG 9.0⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-21839CRITICALCVSS 7.5EG 9.0⚠ KEV2023-01-18
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2021-31010CRITICALCVSS 7.5EG 9.0⚠ KEV2021-08-24
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circum…
- CVE-2024-38094CRITICALCVSS 7.2EG 9.0⚠ KEV2024-07-09
Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2023-0669CRITICALCVSS 7.2EG 9.0⚠ KEV2023-02-06
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version…
- CVE-2020-5741CRITICALCVSS 7.2EG 9.0⚠ KEV2020-05-08
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
- CVE-2026-82222CRITICALCVSS 10.0EG 10.02026-08-28
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
- CVE-2026-69836CRITICALCVSS 10.0EG 10.02026-08-20
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061CRITICALCVSS 10.0EG 10.02026-08-11
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
- CVE-2026-11756CRITICALCVSS 10.0EG 10.02026-07-28
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
- CVE-2026-60366CRITICALCVSS 10.0EG 10.02026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-43633CRITICALCVSS 10.0EG 10.02026-05-19
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code…
- CVE-2026-45829CRITICALCVSS 10.0EG 10.02026-05-18
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_cod…
- CVE-2026-33819CRITICALCVSS 10.0EG 10.02026-04-23
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
- CVE-2026-26333CRITICALCVSS 10.0EG 10.02026-02-13
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SO…
- CVE-2026-25632CRITICALCVSS 10.0EG 10.02026-02-06
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a cust…
- CVE-2026-24815CRITICALCVSS 10.0EG 10.02026-01-27
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFi…
- CVE-2025-14931CRITICALCVSS 10.0EG 10.02025-12-23
Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face smolagents…
- CVE-2025-10363CRITICALCVSS 10.0EG 10.02025-10-06
Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and is fixed in version 11.2.12.00
- CVE-2025-58384CRITICALCVSS 10.0EG 10.02025-09-26
In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the Watchdoc administration interface.
- CVE-2025-42944CRITICALCVSS 10.0EG 10.02025-09-09
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects cou…
- CVE-2024-13980CRITICALCVSS 10.0EG 10.02025-08-27
H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to craft…
- CVE-2025-34153CRITICALCVSS 10.0EG 10.02025-08-13
Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031…
- CVE-2025-34067CRITICALCVSS 10.0EG 10.02025-07-02
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService…
- CVE-2025-34060CRITICALCVSS 10.0EG 10.02025-07-01
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The application passes a user-supplied link parameter directly to …
- CVE-2025-48200CRITICALCVSS 10.0EG 10.02025-05-21
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.
- CVE-2025-30012CRITICALCVSS 10.0EG 10.02025-05-13
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then…
- CVE-2025-32444CRITICALCVSS 10.0EG 10.02025-04-30
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →