This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual I
Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a proj
A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionalit
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality o
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH COD
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality o
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of C
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODE
mrdoc is vulnerable to Deserialization of Untrusted Data
In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to u
Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.
Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized ag
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. Thi
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated atta
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnera
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consum
VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memor
Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catal
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link reso
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Lo
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deser
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administrati
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to
Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserial
A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/d
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to uploa
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use th
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load funct
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could
Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deser
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, wil
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started