Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 43/63
8.1
CVE-2023-47130

Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE)

8.1
CVE-2023-49826

Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce Wor

8.0
CVE-2023-21745

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2023-21762

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2022-4815

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untr

8.0
CVE-2023-28310

Microsoft Exchange Server Remote Code Execution Vulnerability

8.0
CVE-2023-35388

Microsoft Exchange Server Remote Code Execution Vulnerability

8.0
CVE-2023-38182

Microsoft Exchange Server Remote Code Execution Vulnerability

8.0
CVE-2023-36744

Microsoft Exchange Server Remote Code Execution Vulnerability

8.0
CVE-2023-36745

Microsoft Exchange Server Remote Code Execution Vulnerability

8.0
CVE-2023-36756

Microsoft Exchange Server Remote Code Execution Vulnerability

8.0
CVE-2023-36757

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2023-35180

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a

8.0
CVE-2023-35186

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a

8.0
CVE-2023-36035

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2023-36039

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2023-36050

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2023-36439

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8
CVE-2023-21779

Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2023-20944

In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization.

7.8
CVE-2023-27978

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpreta

7.8
CVE-2023-1145

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerabilit

7.8
CVE-2023-1399

N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious

7.8
CVE-2023-26547

The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vu

7.8
CVE-2022-28685

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Pa

7.8
CVE-2022-2561

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022

7.8
CVE-2023-3001

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpret

7.8
CVE-2023-21124

In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to

7.8
CVE-2023-35317

Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

7.8
CVE-2023-3513

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a mali

7.8
CVE-2021-31680

Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml fi

7.8
CVE-2021-31681

Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml fi

7.8
CVE-2023-24621

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by defau

7.8
CVE-2023-28072

Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A

7.8
CVE-2023-35669

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activ

7.8
CVE-2023-34052

VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative acce

7.8
CVE-2023-7018

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

7.5
CVE-2023-21538

.NET Denial of Service Vulnerability

7.5
CVE-2023-21839 KEV

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

7.5
CVE-2022-31710

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger t

7.5
CVE-2023-25558

DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will le

7.5
CVE-2023-26464

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.

7.5
CVE-2023-26548

The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may

7.5
CVE-2023-31058

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In

7.5
CVE-2023-34434

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In

7.5
CVE-2023-24971

IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to caus

7.5
CVE-2023-39396

Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability

7.5
CVE-2023-39410

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constra

7.5
CVE-2023-46227

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache

7.5
CVE-2023-39680

Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute ar

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started