picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completion
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun
picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att
picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met
picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe
picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke
picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth
picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A
picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_lab
picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd
picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in red
picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get funct
picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expres
picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in t
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth
picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle
picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal
Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo
Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev
Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities all
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from
The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `ja
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file meta
An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all
A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubern
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started