Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE)
Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce Wor
Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untr
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a
Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization.
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpreta
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerabilit
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vu
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Pa
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpret
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a mali
Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml fi
Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml fi
An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by defau
Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activ
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative acce
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
.NET Denial of Service Vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger t
DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will le
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to caus
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constra
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache
Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute ar
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started