The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Sto
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malic
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax fu
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerabilit
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object dest
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting bot
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerabil
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerabil
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of thi
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deseriali
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability m
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicio
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write acce
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw wa
Microsoft SharePoint Server Remote Code Execution Vulnerability
Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Ob
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Sched
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/q
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML
An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserial
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust
This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentica
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console a
The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started