Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code exec
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/
There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containe
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occ
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unau
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, ca
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set p
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can sen
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoseria
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of th
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of
JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result i
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to suc
Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerabi
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The aff
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and pr
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Per
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote a
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputSt
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on.
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfa
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerab
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserializati
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provi
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an u
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects,
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by defaul
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability th
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started