Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 9/63
8.8
CVE-2026-66805

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-66808

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-70321

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-58076

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr

8.8
CVE-2026-67587

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports

8.8
CVE-2026-28176

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.

8.8
CVE-2026-16099

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat

8.8
CVE-2026-32465

Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

8.8
CVE-2026-74012

Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: fro

8.8
CVE-2026-76395

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the

8.8
CVE-2026-71513

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle m

8.8
CVE-2026-0551

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

8.8
CVE-2026-78257

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

8.8
CVE-2026-10036

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary c

8.7
CVE-2026-40877

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th

8.6
CVE-2026-45077

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

8.6
CVE-2026-48397

Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e

8.5
CVE-2026-9330

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria

8.5
CVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conne

8.4
CVE-2025-70560

Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us

8.4
CVE-2026-3071

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar

8.4
CVE-2026-37552

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) rec

8.4
CVE-2026-24233

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization

8.4
CVE-2026-28220

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i

8.4
CVE-2026-18634

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B

8.4
CVE-2026-44901

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an

8.3
CVE-2026-58281

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ove

8.2
CVE-2026-44843

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains

8.2
CVE-2026-14637

A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0

8.2
CVE-2026-47623

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ

8.1
CVE-2026-0726

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versi

8.1
CVE-2026-24009

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing

8.1
CVE-2026-0762

GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allow

8.1
CVE-2026-27475

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat

8.1
CVE-2026-27206

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library a

8.1
CVE-2026-27098

Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency

8.1
CVE-2026-27369

Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects

8.1
CVE-2026-2626

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function

8.1
CVE-2026-27096

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O

8.1
CVE-2026-22505

Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.

8.1
CVE-2026-22510

Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue a

8.1
CVE-2026-23971

Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects W

8.1
CVE-2026-25524

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun

8.1
CVE-2026-6023

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecu

8.1
CVE-2026-41316

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init`

8.1
CVE-2026-42471

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal

8.1
CVE-2026-7647

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3

8.1
CVE-2026-7635

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi

8.1
CVE-2026-49121

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the

8.1
CVE-2026-39550

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started