CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,004 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 59 of 61
- CVE-2026-50632CRITICALCVSS 8.1EG 9.82026-06-12
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
- CVE-2026-50633CRITICALCVSS 8.1EG 9.82026-06-12
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. U…
- CVE-2026-50646HIGHCVSS 7.8EG 7.82026-07-14
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-50649HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-50652HIGHCVSS 7.5EG 7.52026-07-14
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- CVE-2026-5127HIGHCVSS 8.8EG 8.82026-05-08
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insuffic…
- CVE-2026-51947CRITICALCVSS 9.8EG 9.82026-07-01
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services…
- CVE-2026-52706CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
- CVE-2026-52751HIGHCVSS 8.8EG 8.82026-06-10
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that…
- CVE-2026-53435HIGHCVSS 8.8EG 8.82026-06-10
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows the…
- CVE-2026-53805CRITICALCVSS 9.8EG 9.82026-06-17
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Pyth…
- CVE-2026-53874CRITICALCVSS 9.8EG 9.82026-06-17
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle …
- CVE-2026-53914CRITICALCVSS 9.8EG 9.82026-06-26
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
- CVE-2026-54117HIGHCVSS 8.8EG 8.82026-07-14
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-54118HIGHCVSS 8.8EG 8.82026-07-14
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-54194CRITICALCVSS 9.8EG 9.82026-06-17
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
- CVE-2026-5426CRITICALCVSS 9.1EG 9.12026-04-16
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState…
- CVE-2026-54469HIGHCVSS 8.8EG 8.82026-07-10
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary comma…
- CVE-2026-54499HIGHCVSS 7.5EG 7.52026-06-19
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., …
- CVE-2026-54512HIGHCVSS 8.1EG 8.12026-06-23
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechan…
- CVE-2026-5473HIGHCVSS 7.0EG 7.02026-04-03
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requi…
- CVE-2026-54806CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- CVE-2026-55009HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-5507MEDIUMCVSS 4.0EG 4.02026-04-09
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability…
- CVE-2026-55153HIGHCVSS 7.1EG 7.12026-07-01
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will const…
- CVE-2026-55175HIGHCVSS 7.5EG 7.52026-07-10
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco mani…
- CVE-2026-55223MEDIUMCVSS 6.3EG 6.32026-06-30
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSour…
- CVE-2026-5536HIGHCVSS 7.3EG 7.32026-04-05
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed f…
- CVE-2026-55944CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- CVE-2026-56031HIGHCVSS 8.1EG 8.12026-06-26
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
- CVE-2026-56032CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
- CVE-2026-56037HIGHCVSS 8.8EG 8.82026-07-02
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.
- CVE-2026-56053HIGHCVSS 8.8EG 8.82026-06-25
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
- CVE-2026-56055HIGHCVSS 8.8EG 8.82026-06-26
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
- CVE-2026-56057CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
- CVE-2026-56121CRITICALCVSS 9.8EG 9.82026-06-24
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function…
- CVE-2026-56304MEDIUMCVSS 6.5EG 6.52026-06-20
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting mali…
- CVE-2026-5659MEDIUMCVSS 6.3EG 6.32026-04-06
A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The manipulation results in deserialization.…
- CVE-2026-56700CRITICALCVSS 9.8EG 9.82026-07-01
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowe…
- CVE-2026-57371HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
- CVE-2026-57516HIGHCVSS 8.8EG 8.82026-07-01
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decod…
- CVE-2026-57527HIGHCVSS 8.8EG 8.82026-06-26
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java…
- CVE-2026-57621CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
- CVE-2026-57677CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
- CVE-2026-57713HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
- CVE-2026-57724CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- CVE-2026-57738CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- CVE-2026-57744CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- CVE-2026-57770CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- CVE-2026-58025CRITICALCVSS 9.8EG 9.82026-07-01
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php.…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →