Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization ca
Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P
Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P
Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren
Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fic
Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detectio
LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious
Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.6
PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a cr
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserial
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user
A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions
A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the
Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at
NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi
NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin
NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user cou
NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a use
NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to lo
NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a use
NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution
NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit o
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo
A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elev
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key
The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate P
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi
NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A succes
A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to v
NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt
An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files.
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A su
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A su
Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-pri
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started