CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,159 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 61 of 64
- CVE-2026-57621CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
- CVE-2026-57677CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
- CVE-2026-57713HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
- CVE-2026-57724CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- CVE-2026-57738CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- CVE-2026-57744CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- CVE-2026-57770CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- CVE-2026-57859HIGHCVSS 7.5EG 7.52026-07-30
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the use…
- CVE-2026-58025CRITICALCVSS 9.8EG 9.82026-07-01
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php.…
- CVE-2026-58076HIGHCVSS 8.8EG 8.82026-08-12
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imp…
- CVE-2026-58126CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.e…
- CVE-2026-58127CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObje…
- CVE-2026-58163CRITICALCVSS 9.1EG 9.12026-07-29
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users ar…
- CVE-2026-58233HIGHCVSS 7.6EG 7.62026-07-14
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remo…
- CVE-2026-58281HIGHCVSS 8.3EG 8.32026-07-11
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58644CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-59124CRITICALCVSS 9.8EG 9.82026-08-11
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- CVE-2026-59242MEDIUMCVSS 5.4EG 5.42026-08-12
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user w…
- CVE-2026-59275MEDIUMCVSS 6.6EG 6.62026-08-27
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Sprin…
- CVE-2026-59306LOWCVSS 3.1EG 3.12026-08-27
Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
- CVE-2026-59307HIGHCVSS 8.0EG 8.02026-08-27
An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration …
- CVE-2026-59518CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- CVE-2026-59521HIGHCVSS 7.2EG 7.22026-07-13
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
- CVE-2026-59544CRITICALCVSS 9.8EG 9.82026-07-23
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- CVE-2026-59827HIGHCVSS 8.8EG 8.82026-07-09
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrar…
- CVE-2026-59940CRITICALCVSS 9.8EG 9.82026-07-24
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general d…
- CVE-2026-6009HIGHCVSS 8.7EG 8.72026-05-19
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
- CVE-2026-6023HIGHCVSS 8.1EG 8.12026-04-22
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with thi…
- CVE-2026-60366CRITICALCVSS 10.0EG 10.02026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60367CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60369CRITICALCVSS 9.9EG 9.92026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60372CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60373HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60392HIGHCVSS 7.8EG 7.82026-08-18
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-60412HIGHCVSS 7.8EG 7.82026-08-18
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with lo…
- CVE-2026-60439HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-61246HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-61484CRITICALCVSS 9.8EG 9.82026-08-05
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users ar…
- CVE-2026-62912MEDIUMCVSS 6.5EG 6.52026-08-11
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- CVE-2026-63077CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-27
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVE-2026-63514HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-63516MEDIUMCVSS 6.5EG 6.52026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-63767CRITICALCVSS 9.8EG 9.82026-07-20
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ…
- CVE-2026-64606CRITICALCVSS 9.8EG 9.82026-07-21
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users a…
- CVE-2026-64608CRITICALCVSS 9.8EG 9.82026-07-21
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input w…
- CVE-2026-64901HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65493HIGHCVSS 7.5EG 7.52026-07-23
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
- CVE-2026-65497HIGHCVSS 7.2EG 7.22026-07-23
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
- CVE-2026-65549HIGHCVSS 7.2EG 7.22026-08-06
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
- CVE-2026-65552CRITICALCVSS 9.8EG 9.82026-08-06
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →