CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 5 of 70
- CVE-2026-93943CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
- CVE-2026-93942CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
- CVE-2026-93941CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
- CVE-2026-93940CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
- CVE-2026-93938CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
- CVE-2026-93937CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
- CVE-2026-93936CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
- CVE-2026-93935CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
- CVE-2026-93934CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
- CVE-2026-93933CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
- CVE-2026-93932CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.
- CVE-2026-93931CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.
- CVE-2026-93930CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.
- CVE-2026-93929CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.
- CVE-2026-93927CRITICALCVSS 9.8EG 9.82026-10-10
Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
- CVE-2026-100730CRITICALCVSS 9.8EG 9.82026-10-09
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows A…
- CVE-2026-88131CRITICALCVSS 9.8EG 9.82026-10-08
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
- CVE-2026-78401CRITICALCVSS 9.8EG 9.82026-10-08
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- CVE-2026-78406CRITICALCVSS 9.8EG 9.82026-10-08
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- CVE-2026-93034CRITICALCVSS 9.8EG 9.82026-10-08
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this v…
- CVE-2026-95606CRITICALCVSS 9.8EG 9.82026-10-07
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
- CVE-2026-105192CRITICALCVSS 9.8EG 9.82026-10-07
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper…
- CVE-2026-76750CRITICALCVSS 9.8EG 9.82026-10-06
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected syste…
- CVE-2026-39797CRITICALCVSS 9.8EG 9.82026-10-06
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
- CVE-2026-97283CRITICALCVSS 9.8EG 9.82026-10-05
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
- CVE-2026-37719CRITICALCVSS 9.8EG 9.82026-10-05
An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component.
- CVE-2026-103877CRITICALCVSS 9.8EG 9.82026-10-02
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java cla…
- CVE-2026-100512CRITICALCVSS 9.8EG 9.82026-09-30
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
- CVE-2026-103395CRITICALCVSS 9.8EG 9.82026-09-30
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and p…
- CVE-2026-97248CRITICALCVSS 9.8EG 9.82026-09-30
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
- CVE-2026-102455CRITICALCVSS 9.8EG 9.82026-09-30
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
- CVE-2026-103041CRITICALCVSS 9.8EG 9.82026-09-29
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary c…
- CVE-2026-103040CRITICALCVSS 9.8EG 9.82026-09-29
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowin…
- CVE-2026-82384CRITICALCVSS 9.8EG 9.82026-09-28
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized dur…
- CVE-2026-96560CRITICALCVSS 9.8EG 9.82026-09-23
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attacke…
- CVE-2026-18163CRITICALCVSS 9.8EG 9.82026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
- CVE-2026-93088CRITICALCVSS 9.8EG 9.82026-09-22
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and pa…
- CVE-2026-19658CRITICALCVSS 9.8EG 9.82026-09-22
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. …
- CVE-2026-94301CRITICALCVSS 9.8EG 9.82026-09-21
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed…
- CVE-2026-81657CRITICALCVSS 9.8EG 9.82026-09-18
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- CVE-2025-66455CRITICALCVSS 9.8EG 9.82026-09-18
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize mes…
- CVE-2026-93467CRITICALCVSS 9.8EG 9.82026-09-18
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
- CVE-2026-20242CRITICALCVSS 9.8EG 9.82026-09-16
A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vul…
- CVE-2025-59953CRITICALCVSS 9.8EG 9.82026-09-16
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC comm…
- CVE-2026-91939CRITICALCVSS 9.8EG 9.82026-09-15
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can expl…
- CVE-2023-54398CRITICALCVSS 9.8EG 9.82026-09-15
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized …
- CVE-2026-90919CRITICALCVSS 9.8EG 9.82026-09-14
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config …
- CVE-2026-78006CRITICALCVSS 9.8EG 9.82026-09-12
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, w…
- CVE-2026-62105CRITICALCVSS 9.8EG 9.82026-09-11
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
- CVE-2026-62103CRITICALCVSS 9.8EG 9.82026-09-11
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →