Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

285
CRITICAL
438
HIGH
80
MEDIUM
3
LOW
848 CVEs · Page 1/17
10.0
CVE-2026-25632

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water dis

10.0
CVE-2026-20131 KEV

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al

10.0
CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

10.0
CVE-2026-45829

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un

10.0
CVE-2026-43633

HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a

10.0
CVE-2026-41104

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform

10.0
CVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

10.0
CVE-2026-11756

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3

10.0
CVE-2026-17061

A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2

10.0
CVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

10.0
CVE-2026-82222

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af

9.9
CVE-2026-34838

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, a

9.9
CVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke

9.9
CVE-2026-59827

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1

9.9
CVE-2026-8476

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m

9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.9
CVE-2026-50517

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

9.9
CVE-2026-50515

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

9.9
CVE-2026-18948

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic

9.8
CVE-2025-47552

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is

9.8
CVE-2025-67911

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti

9.8
CVE-2026-20963 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a

9.8
CVE-2023-7334

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint tha

9.8
CVE-2025-56005

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the

9.8
CVE-2026-23524

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and belo

9.8
CVE-2025-67617

Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af

9.8
CVE-2025-69079

Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows O

9.8
CVE-2026-0760

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. Thi

9.8
CVE-2026-0763

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This

9.8
CVE-2026-0764

GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem

9.8
CVE-2026-0773

Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem

9.8
CVE-2025-40551 KEV

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead

9.8
CVE-2025-40553

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead

9.8
CVE-2025-61140

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

9.8
CVE-2020-37071

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute

9.8
CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

9.8
CVE-2025-69872

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces

9.8
CVE-2026-26221

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workf

9.8
CVE-2026-26333

Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se

9.8
CVE-2026-23542

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T

9.8
CVE-2026-23549

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This

9.8
CVE-2025-67995

Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affe

9.8
CVE-2025-67996

Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects N

9.8
CVE-2025-67997

Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This iss

9.8
CVE-2025-68541

Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects I

9.8
CVE-2025-69301

Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects

9.8
CVE-2025-69329

Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects

9.8
CVE-2025-69370

Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects

9.8
CVE-2025-69371

Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue

9.8
CVE-2025-69372

Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 879 CVE records associated with CWE-502 in our database. Of these, 285 are critical severity, 438 are high severity, and 80 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started