Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 8/63
8.8
CVE-2026-31222

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth

8.8
CVE-2026-31223

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler

8.8
CVE-2026-31224

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier

8.8
CVE-2026-31232

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserializa

8.8
CVE-2026-33110

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-33112

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-35439

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-40357

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-41957

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configu

8.8
CVE-2026-45659 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2025-11993

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve

8.8
CVE-2026-42359

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit

8.8
CVE-2026-7654

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version

8.8
CVE-2026-8365

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_

8.8
CVE-2026-45484

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove

8.8
CVE-2026-52751

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th

8.8
CVE-2026-53435

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar

8.8
CVE-2026-20251

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.1

8.8
CVE-2026-39474

Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

8.8
CVE-2026-39478

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

8.8
CVE-2026-39532

Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.

8.8
CVE-2026-12256

Contributor PHP Object Injection in Avada <= 3.15.3 versions.

8.8
CVE-2025-69130

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

8.8
CVE-2026-41862

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma

8.8
CVE-2026-56053

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

8.8
CVE-2026-56055

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

8.8
CVE-2026-57527

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows

8.8
CVE-2026-57516

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a

8.8
CVE-2026-27060

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is

8.8
CVE-2026-27414

Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

8.8
CVE-2026-56037

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Th

8.8
CVE-2026-14534

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubp

8.8
CVE-2026-46590

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu

8.8
CVE-2026-54469

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability

8.8
CVE-2026-44795

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3

8.8
CVE-2026-57371

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue a

8.8
CVE-2026-57713

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Inje

8.8
CVE-2026-60373

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-60439

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-61246

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-15962

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i

8.8
CVE-2026-65617

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia

8.8
CVE-2026-71281

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src

8.8
CVE-2026-15555

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via

8.8
CVE-2026-63514

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-64901

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65658

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65663

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65665

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65815

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started