CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 46 of 58
- CVE-2025-68047HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.
- CVE-2025-6810CRITICALCVSS 9.8EG 9.82025-07-07
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interac…
- CVE-2025-6811CRITICALCVSS 9.8EG 9.82025-07-07
Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.…
- CVE-2025-68526HIGHCVSS 8.8EG 8.82026-02-20
Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1.
- CVE-2025-68531HIGHCVSS 8.8EG 8.82026-02-20
Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injection.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a thr…
- CVE-2025-68541CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.2.0.
- CVE-2025-68664CRITICALCVSS 9.3EG 9.32025-12-23
LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape diction…
- CVE-2025-68665HIGHCVSS 8.6EG 8.62025-12-23
LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection vulnerability exists in LangChain JS's toJSON()…
- CVE-2025-68853HIGHCVSS 8.8EG 8.82026-02-20
Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: from n/a through <= 9.1.1.
- CVE-2025-68899HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4.
- CVE-2025-68903HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0.
- CVE-2025-68924CRITICALCVSS 7.5EG 9.92026-01-16
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
- CVE-2025-69002HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9.
- CVE-2025-69035HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental Care CPT: from n/a through <= 20.2.
- CVE-2025-69036HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n/a through <= 16.4.
- CVE-2025-69079CRITICALCVSS 9.8EG 9.82026-01-22
Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9.
- CVE-2025-69099HIGHCVSS 8.8EG 8.82026-01-22
Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects North: from n/a through <= 5.7.5.
- CVE-2025-69108CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
- CVE-2025-69111CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
- CVE-2025-69122CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
- CVE-2025-69127CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
- CVE-2025-69130HIGHCVSS 8.8EG 8.82026-06-17
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
- CVE-2025-69276HIGHCVSS 8.8EG 8.82026-01-12
Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.
- CVE-2025-69294HIGHCVSS 8.8EG 8.82026-02-20
Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5.9.
- CVE-2025-69301CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.
- CVE-2025-69328HIGHCVSS 8.8EG 8.82026-02-20
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.
- CVE-2025-69329CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < 1.4.1.
- CVE-2025-69370CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <= 2.5.5.
- CVE-2025-69371CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a through <= 1.6.1.
- CVE-2025-69372CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a through <= 1.6.2.
- CVE-2025-69382CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.
- CVE-2025-69404CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.10.
- CVE-2025-69405CRITICALCVSS 9.8EG 9.82026-02-20
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11.
- CVE-2025-69690CRITICALCVSS 9.1EG 9.12026-05-08
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only avai…
- CVE-2025-69872CRITICALCVSS 9.8EG 9.82026-02-11
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.
- CVE-2025-70559MEDIUMCVSS 6.5EG 6.52026-02-03
pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malic…
- CVE-2025-70560HIGHCVSS 8.4EG 8.42026-02-03
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicio…
- CVE-2025-7099MEDIUMCVSS 5.9EG 5.92025-07-07
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation o…
- CVE-2025-71260HIGHCVSS 8.8EG 8.82026-03-19
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can s…
- CVE-2025-71321CRITICALCVSS 9.8EG 9.82026-06-17
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critic…
- CVE-2025-71339HIGHCVSS 8.1EG 8.12025-12-30
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when lo…
- CVE-2025-71340HIGHCVSS 8.1EG 8.12026-06-25
picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the f…
- CVE-2025-71341HIGHCVSS 8.1EG 8.12026-06-23
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx…
- CVE-2025-71342HIGHCVSS 8.1EG 8.12026-07-04
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in …
- CVE-2025-71343HIGHCVSS 8.1EG 8.12026-07-04
picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection b…
- CVE-2025-71344HIGHCVSS 8.1EG 8.12025-08-26
picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._…
- CVE-2025-71345HIGHCVSS 8.1EG 8.12026-07-04
picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remo…
- CVE-2025-71347HIGHCVSS 8.1EG 8.12026-07-04
picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files t…
- CVE-2025-71348HIGHCVSS 7.8EG 8.12026-06-21
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes…
- CVE-2025-71349HIGHCVSS 8.1EG 8.12026-06-30
picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using trace.Trace.run in t…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →