CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,873 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 37 of 58
- CVE-2025-26967HIGHCVSS 8.8EG 8.82025-03-03
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14.
- CVE-2025-26999HIGHCVSS 8.8EG 8.82025-03-03
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.3.
- CVE-2025-27130HIGHCVSS 8.8EG 8.82025-04-01
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites create…
- CVE-2025-27203CRITICALCVSS 9.6EG 9.62025-07-08
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is cha…
- CVE-2025-27286CRITICALCVSS 9.8EG 9.82025-04-17
Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injection.This issue affects Saoshyant Slider: from n/a through <= 3.0.
- CVE-2025-27287CRITICALCVSS 9.8EG 9.82025-04-17
Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS Quiz: from n/a through <= 2.0.5.
- CVE-2025-27300HIGHCVSS 7.2EG 7.22025-02-24
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1.
- CVE-2025-27301HIGHCVSS 7.2EG 7.22025-02-24
Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-manager allows Object Injection.This issue affects NHR Options Table Manager: from n/a through <= 1.1.2.
- CVE-2025-27511HIGHCVSS 7.2EG 7.22026-06-11
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url lea…
- CVE-2025-27520CRITICALCVSS 9.8EG 9.82025-04-04
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been identified in the latest version (v1.4.2) of…
- CVE-2025-27522MEDIUMCVSS 6.5EG 6.52025-05-28
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache In…
- CVE-2025-27526MEDIUMCVSS 6.5EG 6.52025-05-28
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to up…
- CVE-2025-27528CRITICALCVSS 9.1EG 9.12025-05-28
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary f…
- CVE-2025-27531CRITICALCVSS 9.8EG 9.82025-06-06
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. …
- CVE-2025-27778CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of t…
- CVE-2025-27779CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a…
- CVE-2025-27780CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in model_information.py takes user-supplied input (e.g. a path to a model) and pass that valu…
- CVE-2025-27781CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take user-supplied input (e.g. a path to a model) a…
- CVE-2025-27816CRITICALCVSS 9.8EG 9.82025-03-07
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows Pl…
- CVE-2025-27818HIGHCVSS 8.8EG 8.82025-06-10
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka clien…
- CVE-2025-27819HIGHCVSS 7.5EG 7.52025-06-10
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnera…
- CVE-2025-27925HIGHCVSS 8.5EG 8.52025-03-10
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
- CVE-2025-2855MEDIUMCVSS 4.7EG 4.72025-03-27
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserializ…
- CVE-2025-28961CRITICALCVSS 9.8EG 9.82025-07-16
Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Shortener: from n/a through <= 3.0.7.
- CVE-2025-28970CRITICALCVSS 9.8EG 9.82025-06-27
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects WP Optimize By xTraffic: from n/a through <= 5.1.6.
- CVE-2025-29310CRITICALCVSS 9.8EG 9.82025-03-24
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.
- CVE-2025-2939MEDIUMCVSS 5.6EG 5.62025-06-03
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it p…
- CVE-2025-29783CRITICALCVSS 9.0EG 9.02025-03-19
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute r…
- CVE-2025-29793HIGHCVSS 7.2EG 7.22025-04-08
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-29807HIGHCVSS 8.7EG 8.72025-03-21
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
- CVE-2025-29953CRITICALCVSS 9.8EG 9.82025-04-18
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unb…
- CVE-2025-30012CRITICALCVSS 10.0EG 10.02025-05-13
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then…
- CVE-2025-30023CRITICALCVSS 9.0EG 9.02025-07-11
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
- CVE-2025-30025HIGHCVSS 7.8EG 7.82025-07-11
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
- CVE-2025-30065CRITICALCVSS 9.8EG 9.82025-04-01
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
- CVE-2025-30160HIGHCVSS 7.5EG 7.52025-03-20
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bo…
- CVE-2025-30165HIGHCVSS 8.0EG 8.02025-05-06
vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and co…
- CVE-2025-30284HIGHCVSS 8.4EG 8.42025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could l…
- CVE-2025-30285HIGHCVSS 8.4EG 8.42025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could l…
- CVE-2025-30378HIGHCVSS 7.0EG 7.02025-05-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- CVE-2025-30382HIGHCVSS 7.8EG 7.82025-05-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- CVE-2025-30384HIGHCVSS 7.4EG 7.42025-05-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- CVE-2025-30618CRITICALCVSS 9.8EG 9.82025-06-17
Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows Object Injection.This issue affects Rapyd Payment Extension for WooCommerce: from n/a through <= 1.2.0.
- CVE-2025-30761MEDIUMCVSS 5.9EG 5.92025-07-15
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and 11.0.27; Oracle GraalVM Enterprise Ed…
- CVE-2025-30773HIGHCVSS 7.2EG 7.22025-03-27
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
- CVE-2025-30889HIGHCVSS 8.8EG 8.82025-04-03
Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: from n/a through <= 2.0.13.
- CVE-2025-30892HIGHCVSS 8.8EG 8.82025-04-01
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n/a through <= 1.8.7.
- CVE-2025-30949CRITICALCVSS 9.8EG 9.82025-07-16
Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4.
- CVE-2025-30973CRITICALCVSS 9.8EG 9.82025-07-16
Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This issue affects CoSchool LMS: from n/a through <= 1.4.3.
- CVE-2025-30985CRITICALCVSS 9.8EG 9.82025-04-15
Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →