The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-ca
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untr
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of unt
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and de
Akamai CloudTest before 58.30 allows remote code execution.
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a ga
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary comman
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is pos
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 181
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/c
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it do
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remot
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remo
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.h
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because
A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the C
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShel
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component th
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminSe
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
eDeploy has RCE via cPickle deserialization of untrusted data
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started