Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a
An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre
The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue aff
Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploite
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its A
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unseriali
Microsoft SharePoint Server Remote Code Execution Vulnerability
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that i
The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injec
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows
The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all
The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu
The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver
The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v
The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc
The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS
The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.
The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via d
The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Inje
The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerabil
Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This v
Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulne
Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This
Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution
Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulner
Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilit
The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25
image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().
The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabli
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in co
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started