The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserializa
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configu
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.1
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Th
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubp
Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue a
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Inje
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started