CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 57 of 58
- CVE-2026-56031HIGHCVSS 8.1EG 8.12026-06-26
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
- CVE-2026-56032CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
- CVE-2026-56037HIGHCVSS 8.8EG 8.82026-07-02
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.
- CVE-2026-56053HIGHCVSS 8.8EG 8.82026-06-25
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
- CVE-2026-56055HIGHCVSS 8.8EG 8.82026-06-26
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
- CVE-2026-56057CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
- CVE-2026-56121CRITICALCVSS 9.8EG 9.82026-06-24
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function…
- CVE-2026-56304MEDIUMCVSS 6.5EG 6.52026-06-20
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting mali…
- CVE-2026-5659MEDIUMCVSS 6.3EG 6.32026-04-06
A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The manipulation results in deserialization.…
- CVE-2026-56700CRITICALCVSS 9.8EG 9.82026-07-01
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowe…
- CVE-2026-57371HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
- CVE-2026-57516HIGHCVSS 8.8EG 8.82026-07-01
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decod…
- CVE-2026-57527HIGHCVSS 8.8EG 8.82026-06-26
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java…
- CVE-2026-57621CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
- CVE-2026-57677CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
- CVE-2026-57713HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
- CVE-2026-57724CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- CVE-2026-57738CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- CVE-2026-57744CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- CVE-2026-57770CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- CVE-2026-58025CRITICALCVSS 9.8EG 9.82026-07-01
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php.…
- CVE-2026-58126CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.e…
- CVE-2026-58127CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObje…
- CVE-2026-58233HIGHCVSS 7.6EG 7.62026-07-14
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remo…
- CVE-2026-58281HIGHCVSS 8.3EG 8.32026-07-11
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58644CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-59518CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- CVE-2026-59521HIGHCVSS 7.2EG 7.22026-07-13
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
- CVE-2026-59544CRITICALCVSS 9.8EG 9.82026-07-23
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- CVE-2026-59827HIGHCVSS 8.8EG 8.82026-07-09
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrar…
- CVE-2026-6009HIGHCVSS 8.7EG 8.72026-05-19
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
- CVE-2026-6023HIGHCVSS 8.1EG 8.12026-04-22
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with thi…
- CVE-2026-60366CRITICALCVSS 10.0EG 10.02026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60367CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60369CRITICALCVSS 9.9EG 9.92026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60372CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60373HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60439HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-61246HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-63767CRITICALCVSS 9.8EG 9.82026-07-20
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ…
- CVE-2026-64606CRITICALCVSS 9.8EG 9.82026-07-21
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users a…
- CVE-2026-64608CRITICALCVSS 9.8EG 9.82026-07-21
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input w…
- CVE-2026-65493HIGHCVSS 7.5EG 7.52026-07-23
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
- CVE-2026-65497HIGHCVSS 7.2EG 7.22026-07-23
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
- CVE-2026-6857HIGHCVSS 7.5EG 7.52026-04-22
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading …
- CVE-2026-7301CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
- CVE-2026-7304CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
- CVE-2026-7317MEDIUMCVSS 5.0EG 5.02026-04-28
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The …
- CVE-2026-7566MEDIUMCVSS 6.6EG 6.62026-06-06
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, …
- CVE-2026-7584HIGHCVSS 7.8EG 7.82026-05-01
The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names f…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →