CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 56 of 58
- CVE-2026-49085CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- CVE-2026-49104CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
- CVE-2026-49105CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- CVE-2026-49106CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
- CVE-2026-49107CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
- CVE-2026-49108CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
- CVE-2026-49109CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
- CVE-2026-49121CRITICALCVSS 9.8EG 9.82026-06-01
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary …
- CVE-2026-49286HIGHCVSS 8.1EG 8.12026-06-19
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP s…
- CVE-2026-49740MEDIUMCVSS 6.3EG 6.32026-06-09
TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store …
- CVE-2026-49763CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
- CVE-2026-49765CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
- CVE-2026-49768CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
- CVE-2026-49769CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
- CVE-2026-49770CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
- CVE-2026-49781CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
- CVE-2026-50076CRITICALCVSS 9.1EG 9.12026-06-04
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invok…
- CVE-2026-50509HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-50517CRITICALCVSS 9.9EG 9.92026-07-24
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
- CVE-2026-50522CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-50589HIGHCVSS 7.5EG 7.52026-06-04
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
- CVE-2026-50632CRITICALCVSS 8.1EG 9.82026-06-12
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
- CVE-2026-50633CRITICALCVSS 8.1EG 9.82026-06-12
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. U…
- CVE-2026-50646HIGHCVSS 7.8EG 7.82026-07-14
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-50649HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-50652HIGHCVSS 7.5EG 7.52026-07-14
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- CVE-2026-5127HIGHCVSS 8.8EG 8.82026-05-08
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insuffic…
- CVE-2026-51947CRITICALCVSS 9.8EG 9.82026-07-01
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services…
- CVE-2026-52706CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
- CVE-2026-52751HIGHCVSS 8.8EG 8.82026-06-10
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that…
- CVE-2026-53435HIGHCVSS 8.8EG 8.82026-06-10
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows the…
- CVE-2026-53805CRITICALCVSS 9.8EG 9.82026-06-17
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Pyth…
- CVE-2026-53874CRITICALCVSS 9.8EG 9.82026-06-17
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle …
- CVE-2026-53914CRITICALCVSS 9.8EG 9.82026-06-26
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
- CVE-2026-54117HIGHCVSS 8.8EG 8.82026-07-14
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-54118HIGHCVSS 8.8EG 8.82026-07-14
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-54194CRITICALCVSS 9.8EG 9.82026-06-17
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
- CVE-2026-5426CRITICALCVSS 9.1EG 9.12026-04-16
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState…
- CVE-2026-54469HIGHCVSS 8.8EG 8.82026-07-10
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary comma…
- CVE-2026-54499HIGHCVSS 7.5EG 7.52026-06-19
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., …
- CVE-2026-54512HIGHCVSS 8.1EG 8.12026-06-23
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechan…
- CVE-2026-5473HIGHCVSS 7.0EG 7.02026-04-03
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requi…
- CVE-2026-54806CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- CVE-2026-55009HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-5507MEDIUMCVSS 4.0EG 4.02026-04-09
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability…
- CVE-2026-55153HIGHCVSS 7.1EG 7.12026-07-01
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will const…
- CVE-2026-55175HIGHCVSS 7.5EG 7.52026-07-10
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco mani…
- CVE-2026-55223MEDIUMCVSS 6.3EG 6.32026-06-30
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSour…
- CVE-2026-5536HIGHCVSS 7.3EG 7.32026-04-05
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed f…
- CVE-2026-55944CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →