Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: fro
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle m
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary c
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conne
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) rec
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ove
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versi
Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing
GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allow
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat
Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library a
Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency
Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects
The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O
Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.
Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue a
Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects W
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecu
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init`
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started