Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java obj
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attacke
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10.
Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restrictio
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affec
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it poss
By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the sa
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php
There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request t
Microsoft SharePoint Server Remote Code Execution Vulnerability
SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn6
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. Th
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserial
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objec
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to loca
Microsoft Exchange Server Remote Code Execution Vulnerability
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started