CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 30 of 70
- CVE-2021-35215CRITICALCVSS 8.9EG 9.02021-09-01
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
- CVE-2020-15148CRITICALCVSS 8.9EG 9.02020-09-15
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in th…
- CVE-2024-0692CRITICALCVSS 8.8EG 9.02024-03-01
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
- CVE-2023-32031CRITICALCVSS 8.8EG 9.02023-06-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-20888CRITICALCVSS 8.8EG 9.02023-06-07
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserializatio…
- CVE-2023-21707CRITICALCVSS 8.8EG 9.02023-02-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-25194CRITICALCVSS 8.8EG 9.02023-02-07
A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL…
- CVE-2022-36958CRITICALCVSS 8.8EG 9.02022-10-20
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2021-42125CRITICALCVSS 8.8EG 9.02021-12-07
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
- CVE-2021-29505CRITICALCVSS 8.8EG 9.02021-05-28
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processe…
- CVE-2020-4280CRITICALCVSS 8.8EG 9.02020-10-08
IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java…
- CVE-2022-1471CRITICALCVSS 8.3EG 9.02022-12-01
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor…
- CVE-2020-27131CRITICALCVSS 8.1EG 9.02020-11-17
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to inse…
- CVE-2023-36035CRITICALCVSS 8.0EG 9.02023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2024-30044CRITICALCVSS 7.2EG 9.02024-05-14
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2022-38111CRITICALCVSS 7.2EG 9.02023-02-15
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2020-9496CRITICALCVSS 6.1EG 9.02020-07-15
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
- CVE-2025-49127HIGHCVSS 8.9EG 8.92025-06-06
Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.
- CVE-2024-38018HIGHCVSS 8.8EG 8.92024-09-10
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-50223HIGHCVSS 8.8EG 8.92024-05-03
Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automati…
- CVE-2023-50218HIGHCVSS 8.8EG 8.92024-05-03
Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Igniti…
- CVE-2023-39473HIGHCVSS 8.8EG 8.92024-05-03
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automa…
- CVE-2024-24725HIGHCVSS 8.8EG 8.92024-03-23
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
- CVE-2022-23940HIGHCVSS 8.8EG 8.92022-03-10
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a cra…
- CVE-2022-23302HIGHCVSS 8.8EG 8.92022-01-18
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attack…
- CVE-2021-42130HIGHCVSS 8.8EG 8.92021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
- CVE-2021-24307HIGHCVSS 8.8EG 8.92021-05-24
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying ho…
- CVE-2020-4888HIGHCVSS 8.8EG 8.92021-01-28
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. …
- CVE-2019-12799HIGHCVSS 8.8EG 8.92019-06-13
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can…
- CVE-2019-10867HIGHCVSS 8.8EG 8.92019-04-04
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the …
- CVE-2021-26914HIGHCVSS 8.1EG 8.92021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
- CVE-2024-23478HIGHCVSS 8.0EG 8.92024-02-15
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution.
- CVE-2023-36745HIGHCVSS 8.0EG 8.92023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-4104HIGHCVSS 7.5EG 8.92021-12-14
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causi…
- CVE-2026-62021HIGHCVSS 8.8EG 8.82026-10-10
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
- CVE-2026-105885HIGHCVSS 8.8EG 8.82026-10-10
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
- CVE-2026-104723HIGHCVSS 8.8EG 8.82026-10-10
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes it possible for a…
- CVE-2026-94065HIGHCVSS 8.8EG 8.82026-10-09
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.
- CVE-2026-94064HIGHCVSS 8.8EG 8.82026-10-09
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
- CVE-2026-104392HIGHCVSS 8.8EG 8.82026-10-09
Deserialization of Untrusted Data vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Object Injection.This issue affects Quiz And Survey Master: from n/a through 11.2.7.
- CVE-2026-105436HIGHCVSS 8.8EG 8.82026-10-08
Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
- CVE-2026-95534HIGHCVSS 8.8EG 8.82026-10-07
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, T…
- CVE-2026-106558HIGHCVSS 8.8EG 8.82026-10-07
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker …
- CVE-2026-97188HIGHCVSS 8.8EG 8.82026-10-07
The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object …
- CVE-2026-100511HIGHCVSS 8.8EG 8.82026-10-05
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
- CVE-2026-97257HIGHCVSS 8.8EG 8.82026-10-05
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
- CVE-2026-97284HIGHCVSS 8.8EG 8.82026-10-01
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
- CVE-2026-102377HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
- CVE-2026-97291HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
- CVE-2026-96831HIGHCVSS 8.8EG 8.82026-09-30
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →