Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a netwo
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability t
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Ap
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whi
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started