CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,004 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 60 of 61
- CVE-2026-58126CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.e…
- CVE-2026-58127CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObje…
- CVE-2026-58233HIGHCVSS 7.6EG 7.62026-07-14
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remo…
- CVE-2026-58281HIGHCVSS 8.3EG 8.32026-07-11
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58644CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-59518CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- CVE-2026-59521HIGHCVSS 7.2EG 7.22026-07-13
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
- CVE-2026-59544CRITICALCVSS 9.8EG 9.82026-07-23
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- CVE-2026-59827HIGHCVSS 8.8EG 8.82026-07-09
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrar…
- CVE-2026-6009HIGHCVSS 8.7EG 8.72026-05-19
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
- CVE-2026-6023HIGHCVSS 8.1EG 8.12026-04-22
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with thi…
- CVE-2026-60366CRITICALCVSS 10.0EG 10.02026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60367CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60369CRITICALCVSS 9.9EG 9.92026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60372CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60373HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60439HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-61246HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-63077CRITICALCVSS 9.8EG 9.82026-07-27
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVE-2026-63767CRITICALCVSS 9.8EG 9.82026-07-20
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ…
- CVE-2026-64606CRITICALCVSS 9.8EG 9.82026-07-21
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users a…
- CVE-2026-64608CRITICALCVSS 9.8EG 9.82026-07-21
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input w…
- CVE-2026-65493HIGHCVSS 7.5EG 7.52026-07-23
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
- CVE-2026-65497HIGHCVSS 7.2EG 7.22026-07-23
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
- CVE-2026-6857HIGHCVSS 7.5EG 7.52026-04-22
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading …
- CVE-2026-7301CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
- CVE-2026-7304CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
- CVE-2026-7317MEDIUMCVSS 5.0EG 5.02026-04-28
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The …
- CVE-2026-7566MEDIUMCVSS 6.6EG 6.62026-06-06
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, …
- CVE-2026-7584HIGHCVSS 7.8EG 7.82026-05-01
The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names f…
- CVE-2026-7597MEDIUMCVSS 6.3EG 6.32026-05-01
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack r…
- CVE-2026-7635HIGHCVSS 8.1EG 8.12026-05-13
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the…
- CVE-2026-7637CRITICALCVSS 9.8EG 9.82026-05-20
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attac…
- CVE-2026-7647HIGHCVSS 8.1EG 8.12026-05-02
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter wi…
- CVE-2026-7654HIGHCVSS 8.8EG 8.82026-06-05
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the…
- CVE-2026-7712MEDIUMCVSS 6.3EG 6.32026-05-04
A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exp…
- CVE-2026-7818HIGHCVSS 7.0EG 7.02026-05-11
Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any H…
- CVE-2026-7858CRITICALCVSS 9.8EG 9.82026-06-01
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lea…
- CVE-2026-7871CRITICALCVSS 9.8EG 9.82026-06-30
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
- CVE-2026-7888HIGHCVSS 8.4EG 8.42026-06-03
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP ob…
- CVE-2026-8024CRITICALCVSS 9.8EG 9.82026-06-18
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
- CVE-2026-8135HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the inten…
- CVE-2026-8365HIGHCVSS 8.8EG 8.82026-06-09
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficien…
- CVE-2026-8476CRITICALCVSS 9.9EG 9.92026-07-17
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from dis…
- CVE-2026-8612MEDIUMCVSS 5.3EG 5.32026-05-15
WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constru…
- CVE-2026-8727HIGHCVSS 7.1EG 7.12026-05-19
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution o…
- CVE-2026-8735MEDIUMCVSS 6.3EG 6.32026-05-17
A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack…
- CVE-2026-8751HIGHCVSS 7.3EG 7.32026-05-17
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization…
- CVE-2026-9291HIGHCVSS 7.1EG 7.12026-05-22
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine …
- CVE-2026-9319CRITICALCVSS 9.0EG 9.02026-06-01
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →