CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 8 of 70
- CVE-2025-69127CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
- CVE-2025-69111CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
- CVE-2025-60236CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
- CVE-2025-60231CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
- CVE-2025-60230CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
- CVE-2025-60229CRITICALCVSS 9.8EG 9.82026-06-17
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
- CVE-2026-54806CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- CVE-2026-54194CRITICALCVSS 9.8EG 9.82026-06-17
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
- CVE-2026-52706CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
- CVE-2026-49107CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
- CVE-2026-49075CRITICALCVSS 9.8EG 9.82026-06-17
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
- CVE-2026-42380CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.
- CVE-2026-40725CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
- CVE-2026-39529CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- CVE-2026-27429CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
- CVE-2025-69122CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
- CVE-2025-69108CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
- CVE-2025-60205CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
- CVE-2026-35300CRITICALCVSS 9.8EG 9.82026-06-17
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticat…
- CVE-2026-49765CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
- CVE-2026-49768CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
- CVE-2026-49769CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
- CVE-2026-49770CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
- CVE-2026-49781CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
- CVE-2026-9691CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
- CVE-2026-49085CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- CVE-2026-49104CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
- CVE-2026-49105CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- CVE-2026-49106CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
- CVE-2026-49109CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
- CVE-2026-49763CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
- CVE-2026-27053CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
- CVE-2026-39006CRITICALCVSS 9.8EG 9.82026-06-15
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- CVE-2026-41699CRITICALCVSS 9.8EG 9.82026-06-11
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a pag…
- CVE-2026-26142CRITICALCVSS 9.8EG 9.82026-06-09
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
- CVE-2026-41855CRITICALCVSS 9.8EG 9.82026-06-09
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to una…
- CVE-2026-25550CRITICALCVSS 9.8EG 9.82026-06-04
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singlet…
- CVE-2026-47065CRITICALCVSS 9.8EG 9.82026-06-03
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), J…
- CVE-2026-49121CRITICALCVSS 9.8EG 9.82026-06-01
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary …
- CVE-2026-7858CRITICALCVSS 9.8EG 9.82026-06-01
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lea…
- CVE-2026-10042CRITICALCVSS 9.8EG 9.82026-05-29
manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method…
- CVE-2026-48207CRITICALCVSS 9.8EG 9.82026-05-21
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if i…
- CVE-2026-7637CRITICALCVSS 9.8EG 9.82026-05-20
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attac…
- CVE-2026-24163CRITICALCVSS 9.8EG 9.82026-05-20
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, …
- CVE-2026-24142CRITICALCVSS 9.8EG 9.82026-05-20
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2025-33255CRITICALCVSS 9.8EG 9.82026-05-20
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, an…
- CVE-2026-31072CRITICALCVSS 9.8EG 9.82026-05-19
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantia…
- CVE-2026-7304CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
- CVE-2026-7301CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
- CVE-2021-47952CRITICALCVSS 9.8EG 9.82026-05-16
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →