The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zer
Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerabilit
An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den
Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue a
Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a thro
Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability
LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserializ
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the L
Microsoft Exchange Server Remote Code Execution Vulnerability
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerab
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-p
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which coul
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can ex
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker t
The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the s
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not proper
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro:
Azure DevOps Server Remote Code Execution Vulnerability
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could
JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.
Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitra
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Py
Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects
Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a throu
Azure Data Box Gateway Remote Code Execution Vulnerability
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your Wo
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some un
A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this iss
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown pr
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the
A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability i
A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown
Microsoft SharePoint Server Remote Code Execution Vulnerability
An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration prope
Microsoft Exchange Server Information Disclosure Vulnerability
A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of th
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. Th
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant
vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known se
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This c
Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started