CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 4 of 70
- CVE-2024-20253CRITICALCVSS 9.9EG 9.92024-01-26
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper proce…
- CVE-2023-30899CRITICALCVSS 9.9EG 9.92023-05-09
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Vi…
- CVE-2023-30898CRITICALCVSS 9.9EG 9.92023-05-09
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Vi…
- CVE-2022-38652CRITICALCVSS 9.9EG 9.92022-11-12
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host …
- CVE-2021-29485CRITICALCVSS 9.9EG 9.92021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a maliciously crafted Java deserialization gadget chain leveraged against the Ratpack session …
- CVE-2021-21345CRITICALCVSS 9.9EG 9.92021-03-23
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulati…
- CVE-2026-12650CRITICALCVSS 8.8EG 9.92026-09-08
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2025-23120CRITICALCVSS 8.8EG 9.92025-03-20
A vulnerability allowing remote code execution (RCE) for domain users.
- CVE-2023-52219CRITICALCVSS 8.8EG 9.92024-01-08
Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.
- CVE-2023-52182CRITICALCVSS 8.8EG 9.92023-12-31
Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.
- CVE-2023-51470CRITICALCVSS 8.8EG 9.92023-12-29
Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.
- CVE-2023-51422CRITICALCVSS 8.8EG 9.92023-12-29
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automat…
- CVE-2023-5183CRITICALCVSS 8.8EG 9.92023-09-27
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoi…
- CVE-2025-68924CRITICALCVSS 7.5EG 9.92026-01-16
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
- CVE-2026-81797CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
- CVE-2026-78535CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
- CVE-2026-78533CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
- CVE-2026-78531CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
- CVE-2026-78529CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
- CVE-2026-66569CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
- CVE-2026-66568CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
- CVE-2026-66567CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
- CVE-2026-66565CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.
- CVE-2026-66564CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
- CVE-2026-66563CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.
- CVE-2026-66483CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.
- CVE-2026-66482CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.
- CVE-2026-62125CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions.
- CVE-2026-62124CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in N7 | Golf Club Sports & Events <= 2.21 versions.
- CVE-2026-62123CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Invetex <= 2.18 versions.
- CVE-2026-62120CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Law Office <= 3.20 versions.
- CVE-2026-62090CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in WineShop <= 3.20 versions.
- CVE-2026-62087CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Equadio <= 1.1.4 versions.
- CVE-2026-62086CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Juno <= 2.25 versions.
- CVE-2026-62077CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Avala <= 1.1.4 versions.
- CVE-2026-62076CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Kalles <= 1.1.7.1 versions.
- CVE-2026-62054CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Yacht Rental <= 2.6 versions.
- CVE-2026-62053CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Wine House <= 3.20 versions.
- CVE-2026-62052CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Tipsy <= 1.6 versions.
- CVE-2026-62051CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Stargaze <= 1.10 versions.
- CVE-2026-62050CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Splendour <= 1.23 versions.
- CVE-2026-42723CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
- CVE-2026-42719CRITICALCVSS 9.8EG 9.82026-10-10
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
- CVE-2026-42718CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
- CVE-2026-42716CRITICALCVSS 9.8EG 9.82026-10-10
Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
- CVE-2026-104398CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a t…
- CVE-2026-62045CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
- CVE-2026-62046CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
- CVE-2026-93945CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
- CVE-2026-93944CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →