NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali
Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes th
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache sess
Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-pl
manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability th
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) d
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerabi
The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 20
Deserialization of Untrusted Data vulnerability in DTStack chunjun (chunjun-core/src/main/java/com/dtstack/chunjun/util
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an a
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from th
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3
FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize dat
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input.
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configure
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and
TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grp
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbi
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to in
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauth
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patc
The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can c
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and J
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Appli
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulne
The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() functi
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserial
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an a
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\
Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and p
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which al
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started