CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 33 of 61
- CVE-2024-49070HIGHCVSS 7.4EG 7.42024-12-12
Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2024-49147CRITICALCVSS 9.3EG 9.32024-12-12
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
- CVE-2024-49218CRITICALCVSS 9.8EG 9.82024-10-16
Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.
- CVE-2024-49222CRITICALCVSS 9.8EG 9.82025-01-07
Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0.
- CVE-2024-49226HIGHCVSS 8.8EG 8.82024-10-16
Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17.
- CVE-2024-49227CRITICALCVSS 9.8EG 9.82024-10-16
Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4.
- CVE-2024-49318CRITICALCVSS 9.8EG 9.82024-10-17
Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0.
- CVE-2024-49332CRITICALCVSS 9.8EG 9.82024-10-20
Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4.
- CVE-2024-49375CRITICALCVSS 9.0EG 9.02025-01-14
Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prereq…
- CVE-2024-49624CRITICALCVSS 9.8EG 9.82024-10-20
Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1.
- CVE-2024-49625CRITICALCVSS 9.8EG 9.82024-10-20
Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0.
- CVE-2024-49626CRITICALCVSS 9.8EG 9.82024-10-20
Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.This issue affects Shipyaari Shipping Management: from n/a through <= 1.2.
- CVE-2024-49684HIGHCVSS 7.2EG 7.22024-10-23
Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.
- CVE-2024-49688CRITICALCVSS 9.8EG 9.82025-01-21
Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.
- CVE-2024-49699HIGHCVSS 8.8EG 8.82025-01-21
Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.
- CVE-2024-49744HIGHCVSS 7.8EG 7.82025-01-21
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution p…
- CVE-2024-4978CRITICALCVSS 8.4EG 9.0⚠ KEV2024-05-23
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized Po…
- CVE-2024-49849HIGHCVSS 7.8EG 7.82024-12-10
A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18…
- CVE-2024-5016HIGHCVSS 7.2EG 7.22024-06-25
In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM. The vulnerability exists in the main message processing …
- CVE-2024-50408HIGHCVSS 8.8EG 8.82024-10-28
Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.
- CVE-2024-50416HIGHCVSS 8.8EG 8.82024-10-28
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through <= 1.2.6.
- CVE-2024-50507CRITICALCVSS 9.8EG 9.82024-10-30
Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.
- CVE-2024-5085HIGHCVSS 8.1EG 8.12024-05-23
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possibl…
- CVE-2024-51363CRITICALCVSS 9.8EG 9.82024-12-03
Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.
- CVE-2024-52046CRITICALCVSS 9.8EG 9.82024-12-25
The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deseri…
- CVE-2024-52306HIGHCVSS 7.6EG 7.62024-11-13
FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.
- CVE-2024-52338CRITICALCVSS 9.8EG 9.82024-11-28
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from un…
- CVE-2024-52409CRITICALCVSS 9.8EG 9.82024-11-16
Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3.
- CVE-2024-52410CRITICALCVSS 9.8EG 9.82024-11-16
Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0.
- CVE-2024-52411CRITICALCVSS 9.8EG 9.82024-11-16
Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allows Object Injection.This issue affects Advanced Personalization: from n/a through <= 1.1.2.
- CVE-2024-52412CRITICALCVSS 9.8EG 9.82024-11-16
Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from n/a through 1.0.8.1.
- CVE-2024-52413CRITICALCVSS 9.8EG 9.82024-11-16
Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue affects Airin Blog: from n/a through <= 1.6.1.
- CVE-2024-52414CRITICALCVSS 9.8EG 9.82024-11-16
Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through <= 5.3.18.
- CVE-2024-52430CRITICALCVSS 9.8EG 9.82024-11-18
Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.
- CVE-2024-52432CRITICALCVSS 9.8EG 9.82024-11-18
Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4.
- CVE-2024-52433CRITICALCVSS 9.8EG 9.82024-11-18
Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.
- CVE-2024-52439CRITICALCVSS 9.8EG 9.82024-11-20
Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This issue affects Team Rosters: from n/a through <= 4.8.2.
- CVE-2024-52440CRITICALCVSS 9.8EG 9.82024-11-20
Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocommerce allows Object Injection.This issue affects Xpresslane Fast Checkout: from n/a through <= 1.0.0.
- CVE-2024-52443CRITICALCVSS 9.8EG 9.82024-11-20
Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue affects Geolocator: from n/a through <= 1.1.
- CVE-2024-52445HIGHCVSS 8.8EG 8.82024-11-20
Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object Injection.This issue affects QRMenu Restaurant QR Menu Lite: from n/a through <= 1.0.4.
- CVE-2024-52577CRITICALCVSS 9.0EG 9.02025-02-14
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulner…
- CVE-2024-53247HIGHCVSS 8.8EG 8.82024-12-10
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk ro…
- CVE-2024-53326HIGHCVSS 7.3EG 7.32026-05-08
LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.
- CVE-2024-5335CRITICALCVSS 9.8EG 9.82024-08-21
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the…
- CVE-2024-53477CRITICALCVSS 9.8EG 9.82024-12-02
JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java
- CVE-2024-5351MEDIUMCVSS 6.3EG 6.32024-05-26
A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getValueFromJs of the component Javascript Handler. The manipulation leads to deserialization. T…
- CVE-2024-5352MEDIUMCVSS 6.3EG 6.32024-05-26
A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been rated as critical. Affected by this issue is the function validationRules of the component com.anjiplus.template.gaea.business.modules.datasetparam.controller.DataSe…
- CVE-2024-53673HIGHCVSS 8.1EG 8.12024-11-26
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
- CVE-2024-53909CRITICALCVSS 9.8EG 9.82024-11-24
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
- CVE-2024-53910CRITICALCVSS 9.8EG 9.82024-11-24
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →