EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water dis
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, a
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint tha
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and belo
Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af
Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows O
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. Thi
GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This
GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem
Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workf
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This
Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affe
Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects N
Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This iss
Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects I
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue
Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 879 CVE records associated with CWE-502 in our database. Of these, 285 are critical severity, 438 are high severity, and 80 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started