CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code exe
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code
A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inj
The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PH
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper veri
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system c
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks,
In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated atta
Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.
The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via des
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserializ
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented Sy
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted
Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX i
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthentica
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticat
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize(
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to pe
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instan
Microsoft Exchange Server Remote Code Execution Vulnerability
Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedic
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to ru
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-cr
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgr
A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all ve
A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I
In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local esca
In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configur
In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` f
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unseria
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started