CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 27 of 70
- CVE-2018-1904CRITICALCVSS 8.1EG 9.82018-12-11
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
- CVE-2023-1399CRITICALCVSS 7.8EG 9.82023-03-27
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.
- CVE-2017-9844CRITICALCVSS 7.5EG 9.82017-07-12
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor …
- CVE-2022-0749CRITICALCVSS 7.4EG 9.82022-03-17
This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appro…
- CVE-2018-1851CRITICALCVSS 7.3EG 9.82018-10-31
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could …
- CVE-2025-68038CRITICALCVSS 7.2EG 9.82025-12-24
Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through < 5.9.14.
- CVE-2022-32521CRITICALCVSS 7.1EG 9.82023-01-30
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server. Affected Products: Data Center Expert (Versions prio…
- CVE-2023-26234CRITICALCVSS 6.6EG 9.82023-02-21
JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.
- CVE-2023-51642CRITICALCVSS 6.3EG 9.82024-11-22
Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to…
- CVE-2023-51641CRITICALCVSS 6.3EG 9.82024-11-22
Allegra renderFieldMatch Deserialization of Unstrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required…
- CVE-2024-0937CRITICALCVSS 6.3EG 9.82024-01-26
A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. Th…
- CVE-2022-4890CRITICALCVSS 6.3EG 9.82023-01-16
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The man…
- CVE-2025-48086CRITICALCVSS 5.5EG 9.82025-11-06
Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3.
- CVE-2022-2870CRITICALCVSS 4.1EG 9.82022-08-17
A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the publ…
- CVE-2026-54752CRITICALCVSS 9.6EG 9.62026-09-17
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_…
- CVE-2026-78683CRITICALCVSS 9.6EG 9.62026-08-25
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=Fals…
- CVE-2026-34659CRITICALCVSS 9.6EG 9.62026-05-12
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul…
- CVE-2026-27303CRITICALCVSS 9.6EG 9.62026-04-14
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2025-27203CRITICALCVSS 9.6EG 9.62025-07-08
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is cha…
- CVE-2024-28074CRITICALCVSS 9.6EG 9.62024-07-17
It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerab…
- CVE-2024-3568CRITICALCVSS 9.6EG 9.62024-04-10
The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code …
- CVE-2023-36825CRITICALCVSS 9.6EG 9.62023-07-11
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deseria…
- CVE-2021-23894CRITICALCVSS 9.6EG 9.62021-06-02
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully construct…
- CVE-2021-21249CRITICALCVSS 9.6EG 9.62021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by d…
- CVE-2021-21247CRITICALCVSS 9.6EG 9.62021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener decodes and deserialize…
- CVE-2023-51545CRITICALCVSS 8.8EG 9.62023-12-29
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and recruitments.This issue affects Job Manager & Career – Manage job board listings, and…
- CVE-2019-7539CRITICALCVSS 8.8EG 9.62019-03-21
A code injection issue was discovered in ipycache through 2016-05-31.
- CVE-2026-48909CRITICALCVSS 9.5EG 9.52026-06-20
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.
- CVE-2025-15579CRITICALCVSS 9.5EG 9.52026-02-18
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory …
- CVE-2025-47292CRITICALCVSS 9.5EG 9.52025-05-14
Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can b…
- CVE-2025-1077CRITICALCVSS 9.5EG 9.52025-02-07
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in spe…
- CVE-2025-64393CRITICALCVSS 9.4EG 9.42026-10-07
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
- CVE-2026-81867CRITICALCVSS 9.4EG 9.42026-09-28
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary …
- CVE-2026-52777CRITICALCVSS 9.4EG 9.42026-07-09
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.
- CVE-2026-44963CRITICALCVSS 9.4EG 9.42026-06-09
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
- CVE-2026-33454CRITICALCVSS 9.4EG 9.42026-04-27
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not con…
- CVE-2025-34292CRITICALCVSS 9.4EG 9.42025-10-27
Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in …
- CVE-2026-107104CRITICALCVSS 9.3EG 9.32026-10-07
This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the…
- CVE-2026-67399CRITICALCVSS 9.3EG 9.32026-09-14
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
- CVE-2026-55220CRITICALCVSS 9.3EG 9.32026-08-28
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspotim…
- CVE-2026-51106CRITICALCVSS 9.3EG 9.32026-08-26
An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
- CVE-2026-77138CRITICALCVSS 9.3EG 9.32026-08-25
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, lead…
- CVE-2025-15610CRITICALCVSS 9.3EG 9.32026-04-15
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.
- CVE-2026-34615CRITICALCVSS 9.3EG 9.32026-04-14
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabili…
- CVE-2026-26220CRITICALCVSS 9.3EG 9.32026-02-17
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directl…
- CVE-2026-26215CRITICALCVSS 9.3EG 9.32026-02-11
manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{met…
- CVE-2026-23746CRITICALCVSS 9.3EG 9.32026-01-15
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCa…
- CVE-2025-68664CRITICALCVSS 9.3EG 9.32025-12-23
LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape diction…
- CVE-2025-34414CRITICALCVSS 9.3EG 9.32025-12-09
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled …
- CVE-2025-66571CRITICALCVSS 9.3EG 9.32025-12-04
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter is passed to PHP unserialize() without proper handling, allowing remote, unauthenticated …
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →