CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 31 of 61
- CVE-2024-34433MEDIUMCVSS 4.4EG 4.42024-05-14
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.
- CVE-2024-34515HIGHCVSS 8.8EG 8.82024-05-05
image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().
- CVE-2024-3467HIGHCVSS 7.8EG 7.82024-06-12
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by…
- CVE-2024-3468HIGHCVSS 8.4EG 8.42024-06-12
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content…
- CVE-2024-34751MEDIUMCVSS 4.4EG 4.42024-05-16
Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.
- CVE-2024-3483HIGHCVSS 7.8EG 7.82024-05-15
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.
- CVE-2024-34997HIGHCVSS 7.5EG 7.52024-05-17
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching o…
- CVE-2024-35249HIGHCVSS 8.8EG 8.82024-06-11
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
- CVE-2024-3568CRITICALCVSS 9.6EG 9.62024-04-10
The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code …
- CVE-2024-35780HIGHCVSS 8.5EG 8.52024-06-19
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
- CVE-2024-3591MEDIUMCVSS 6.5EG 6.52024-05-01
The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blo…
- CVE-2024-36131HIGHCVSS 8.8EG 8.82024-08-07
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
- CVE-2024-36528HIGHCVSS 8.8EG 8.82024-06-10
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
- CVE-2024-36984HIGHCVSS 8.8EG 8.82024-07-01
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitr…
- CVE-2024-37052HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
- CVE-2024-37053HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
- CVE-2024-37054HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.
- CVE-2024-37055HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.
- CVE-2024-37056HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted wit…
- CVE-2024-37057HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.
- CVE-2024-37058HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted wi…
- CVE-2024-37059HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.
- CVE-2024-37060HIGHCVSS 8.8EG 8.82024-06-04
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.
- CVE-2024-37062HIGHCVSS 7.8EG 7.82024-06-04
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.
- CVE-2024-37064HIGHCVSS 7.8EG 7.82024-06-04
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.
- CVE-2024-37065HIGHCVSS 7.8EG 7.82024-06-04
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
- CVE-2024-37099CRITICALCVSS 10.0EG 10.02024-08-19
Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.
- CVE-2024-37285CRITICALCVSS 9.1EG 9.12024-11-14
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasti…
- CVE-2024-37288CRITICALCVSS 9.9EG 9.92024-09-09
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.e…
- CVE-2024-37361CRITICALCVSS 9.9EG 9.92025-02-20
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, d…
- CVE-2024-3740MEDIUMCVSS 6.3EG 6.32024-04-13
A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file /adminPage/conf/reload. The manipulation of the argument nginxExe leads to deserializatio…
- CVE-2024-37502MEDIUMCVSS 5.4EG 5.42024-07-09
Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.
- CVE-2024-38018HIGHCVSS 8.8EG 8.92024-09-10
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2024-38023HIGHCVSS 7.2EG 7.92024-07-09
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2024-38024HIGHCVSS 7.2EG 7.72024-07-09
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2024-38094CRITICALCVSS 7.2EG 9.0⚠ KEV2024-07-09
Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2024-38759MEDIUMCVSS 5.4EG 5.42024-07-22
Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a through 3.2.2.
- CVE-2024-39334MEDIUMCVSS 6.5EG 6.52024-06-23
MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the details of this transaction in the client, files can be written to the computer on which the client p…
- CVE-2024-3954HIGHCVSS 8.8EG 8.82024-05-14
The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level ac…
- CVE-2024-39630MEDIUMCVSS 5.5EG 5.52024-08-01
Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.
- CVE-2024-39636HIGHCVSS 8.3EG 8.32024-08-01
Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.
- CVE-2024-3967HIGHCVSS 7.6EG 7.62024-05-15
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.
- CVE-2024-39673MEDIUMCVSS 6.8EG 6.82024-07-25
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-39705CRITICALCVSS 9.8EG 9.82024-06-27
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
- CVE-2024-39780HIGHCVSS 7.8EG 8.42025-04-02
A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and ear…
- CVE-2024-4019MEDIUMCVSS 6.3EG 6.32024-04-20
A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. It is…
- CVE-2024-4044HIGHCVSS 7.8EG 7.82024-05-14
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially craft…
- CVE-2024-40624CRITICALCVSS 9.8EG 9.82024-07-15
TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled cookies.…
- CVE-2024-40711CRITICALCVSS 9.8EG 9.8⚠ KEV2024-09-07
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- CVE-2024-41151HIGHCVSS 8.8EG 8.82024-11-18
Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →