Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 10/63
8.1
CVE-2026-39551

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbe

8.1
CVE-2026-39555

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk

8.1
CVE-2026-42211

React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps

8.1
CVE-2026-41855

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin

8.1
CVE-2026-41731

JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a

8.1
CVE-2026-41732

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac

8.1
CVE-2026-41699

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a

8.1
CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache

8.1
CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec

8.1
CVE-2026-27333

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

8.1
CVE-2026-42687

Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.

8.1
CVE-2026-39443

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

8.1
CVE-2026-39446

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

8.1
CVE-2026-39539

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

8.1
CVE-2026-39545

Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.

8.1
CVE-2026-39554

Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.

8.1
CVE-2026-39557

Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.

8.1
CVE-2026-39567

Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.

8.1
CVE-2026-39573

Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.

8.1
CVE-2026-39580

Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.

8.1
CVE-2026-40735

Unauthenticated PHP Object Injection in Reina <= 2.1 versions.

8.1
CVE-2026-40736

Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.

8.1
CVE-2026-40739

Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.

8.1
CVE-2026-40751

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

8.1
CVE-2026-40753

Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.

8.1
CVE-2026-40754

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

8.1
CVE-2026-40755

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

8.1
CVE-2026-40758

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

8.1
CVE-2026-40759

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

8.1
CVE-2026-40760

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

8.1
CVE-2026-40761

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

8.1
CVE-2026-39442

Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

8.1
CVE-2026-39445

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

8.1
CVE-2026-39556

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

8.1
CVE-2026-39560

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

8.1
CVE-2026-39576

Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

8.1
CVE-2026-40733

Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

8.1
CVE-2026-40738

Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

8.1
CVE-2026-40752

Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

8.1
CVE-2026-40756

Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

8.1
CVE-2026-40757

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

8.1
CVE-2026-49286

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/

8.1
CVE-2025-71348

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config funct

8.1
CVE-2025-71357

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in

8.1
CVE-2025-71378

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attacker

8.1
CVE-2025-71339

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, a

8.1
CVE-2025-71344

picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function

8.1
CVE-2025-71358

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entit

8.1
CVE-2025-71341

picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attac

8.1
CVE-2025-71365

picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function thro

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started