CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 26 of 70
- CVE-2016-8736CRITICALCVSS 9.8EG 9.82017-10-12
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
- CVE-2017-0903CRITICALCVSS 9.8EG 9.82017-10-11
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used…
- CVE-2017-14702CRITICALCVSS 9.8EG 9.82017-09-30
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.
- CVE-2017-10932CRITICALCVSS 9.8EG 9.82017-09-28
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Ap…
- CVE-2017-14035CRITICALCVSS 9.8EG 9.82017-08-30
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
- CVE-2017-11153CRITICALCVSS 9.8EG 9.82017-08-08
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
- CVE-2017-9785CRITICALCVSS 9.8EG 9.82017-07-20
Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.
- CVE-2016-4000CRITICALCVSS 9.8EG 9.82017-07-06
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
- CVE-2017-9830CRITICALCVSS 9.8EG 9.82017-06-27
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listens on a TCP port and deserializes objects sent by TCP client…
- CVE-2017-9424CRITICALCVSS 9.8EG 9.82017-06-22
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
- CVE-2016-7050CRITICALCVSS 9.8EG 9.82017-06-08
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
- CVE-2016-3690CRITICALCVSS 9.8EG 9.82017-06-08
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
- CVE-2017-5878CRITICALCVSS 9.8EG 9.82017-06-08
The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data.
- CVE-2017-4914CRITICALCVSS 9.8EG 9.82017-06-07
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
- CVE-2017-9363CRITICALCVSS 9.8EG 9.82017-06-02
Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.
- CVE-2017-7504CRITICALCVSS 9.8EG 9.82017-05-19
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, whi…
- CVE-2017-5645CRITICALCVSS 9.8EG 9.82017-04-17
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrar…
- CVE-2016-0779CRITICALCVSS 9.8EG 9.82017-04-11
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.
- CVE-2017-5983CRITICALCVSS 9.8EG 9.82017-04-10
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a craft…
- CVE-2016-6809CRITICALCVSS 9.8EG 9.82017-04-06
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
- CVE-2016-8749CRITICALCVSS 9.8EG 9.82017-03-28
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
- CVE-2014-8731CRITICALCVSS 9.8EG 9.82017-03-23
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.
- CVE-2017-5929CRITICALCVSS 9.8EG 9.82017-03-13
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
- CVE-2017-3159CRITICALCVSS 9.8EG 9.82017-03-07
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
- CVE-2017-5830CRITICALCVSS 9.8EG 9.82017-03-03
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
- CVE-2016-0360CRITICALCVSS 9.8EG 9.82017-02-15
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM…
- CVE-2017-5954CRITICALCVSS 9.8EG 9.82017-02-10
An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked…
- CVE-2017-5941CRITICALCVSS 9.8EG 9.82017-02-09
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked …
- CVE-2016-6199CRITICALCVSS 9.8EG 9.82017-02-07
ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
- CVE-2016-9865CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), …
- CVE-2016-6620CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object inst…
- CVE-2016-5019CRITICALCVSS 9.8EG 9.82016-10-03
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
- CVE-2016-6330CRITICALCVSS 9.8EG 9.82016-09-27
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserial…
- CVE-2016-7124CRITICALCVSS 9.8EG 9.82016-09-12
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data…
- CVE-2016-1114CRITICALCVSS 9.8EG 9.82016-05-11
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
- CVE-2015-6420CRITICALCVSS 9.8EG 9.82015-12-15
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; …
- CVE-2003-0791CRITICALCVSS 9.8EG 9.82003-10-07
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
- CVE-2018-15616CRITICALCVSS 9.0EG 9.82018-10-17
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform …
- CVE-2025-50004CRITICALCVSS 8.8EG 9.82026-01-22
Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.
- CVE-2025-53586CRITICALCVSS 8.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through <= 1.9.1.
- CVE-2025-49386CRITICALCVSS 8.8EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue affects Preserve Code Formatting: from n/a through <= 4.0.1.
- CVE-2025-24661CRITICALCVSS 8.8EG 9.82025-02-03
Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Injection.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.1.8.
- CVE-2023-6933CRITICALCVSS 8.8EG 9.82024-02-05
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP O…
- CVE-2022-41779CRITICALCVSS 8.8EG 9.82022-10-31
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets …
- CVE-2022-2830CRITICALCVSS 8.8EG 9.82022-09-05
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Pr…
- CVE-2021-32935CRITICALCVSS 8.8EG 9.82022-05-23
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.
- CVE-2022-23307CRITICALCVSS 8.8EG 9.82022-01-18
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
- CVE-2024-31094CRITICALCVSS 8.5EG 9.82024-03-31
Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
- CVE-2026-50633CRITICALCVSS 8.1EG 9.82026-06-12
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. U…
- CVE-2026-50632CRITICALCVSS 8.1EG 9.82026-06-12
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →