Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 5/63
9.8
CVE-2026-50522 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a

9.8
CVE-2026-54117

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-54118

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-58644 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a

9.8
CVE-2026-55944

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a netwo

9.8
CVE-2026-63767

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability t

9.8
CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa

9.8
CVE-2026-64606

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb

9.8
CVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.8
CVE-2026-60372

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.8
CVE-2026-59544

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

9.8
CVE-2026-63077 KEV

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin

9.8
CVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Ap

9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whi

9.8
CVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo

9.8
CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co

9.8
CVE-2026-15969

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl

9.8
CVE-2026-15976

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi

9.8
CVE-2026-68771

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic

9.8
CVE-2026-69098

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows

9.8
CVE-2026-70554

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod

9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac

9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit

9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

9.8
CVE-2026-65552

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

9.8
CVE-2026-65556

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

9.8
CVE-2026-65571

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

9.8
CVE-2026-65572

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

9.8
CVE-2026-65573

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

9.8
CVE-2026-65574

Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

9.8
CVE-2026-65575

Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

9.8
CVE-2026-65576

Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

9.8
CVE-2026-65577

Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

9.8
CVE-2026-65578

Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

9.8
CVE-2026-65579

Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

9.8
CVE-2026-65581

Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

9.8
CVE-2026-16258

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u

9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from

9.8
CVE-2026-59124

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to

9.8
CVE-2026-28149

Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

9.8
CVE-2024-13784

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection

9.8
CVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to

9.8
CVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

9.8
CVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

9.8
CVE-2026-73376

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

9.8
CVE-2026-73380

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

9.8
CVE-2026-73397

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

9.8
CVE-2026-73364

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

9.8
CVE-2026-73389

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started