Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 6/63
9.8
CVE-2026-76850

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch

9.8
CVE-2026-66583

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

9.8
CVE-2026-66672

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

9.8
CVE-2026-73993

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

9.8
CVE-2026-4703

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all ve

9.8
CVE-2026-66650

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

9.8
CVE-2026-32563

Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

9.8
CVE-2026-78262

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

9.8
CVE-2026-78265

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

9.8
CVE-2026-79657

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir

9.8
CVE-2026-80428

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components

9.8
CVE-2026-78286

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

9.8
CVE-2026-78292

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

9.8
CVE-2026-78032

SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with

9.6
CVE-2026-27303

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that

9.6
CVE-2026-34659

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerabili

9.6
CVE-2026-78683

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition

9.4
CVE-2026-33454

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the

9.3
CVE-2026-34615

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that

9.3
CVE-2026-51106

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.c

9.1
CVE-2026-25923

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to

9.1
CVE-2026-27685

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content

9.1
CVE-2026-25769

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1

9.1
CVE-2026-5426

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all

9.1
CVE-2025-69690

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob

9.1
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as [email protected] were not serializ

9.1
CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Jav

9.1
CVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d

9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0

9.1
CVE-2026-76404

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands

9.0
CVE-2025-33244

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted

9.0
CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of

9.0
CVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit

9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable

9.0
CVE-2026-70426

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2

8.8
CVE-2025-31047

Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Them

8.8
CVE-2025-47553

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is

8.8
CVE-2025-69276

Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection

8.8
CVE-2025-50004

Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issu

8.8
CVE-2025-67619

Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issu

8.8
CVE-2025-68047

Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issu

8.8
CVE-2025-68899

Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects

8.8
CVE-2025-68903

Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects An

8.8
CVE-2025-69002

Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affec

8.8
CVE-2025-69035

Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injecti

8.8
CVE-2025-69036

Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.T

8.8
CVE-2025-69099

Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects

8.8
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `wei

8.8
CVE-2026-24954

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This

8.8
CVE-2026-0910

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started