A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the fi
NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data.
MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load()
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed i
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges local
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows atta
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low pri
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low pri
Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This
Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability a
BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py d
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load sta
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted a
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated.
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execut
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio
Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-ser
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheu
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheu
Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules),
The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1
Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object In
The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerabi
pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTI
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when des
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deseri
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started