CWE-502— Deserialization of Untrusted Data
2,472 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 34 of 50
- CVE-2024-9664HIGHCVSS 7.2EG 7.22025-02-07
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, wi…
- CVE-2024-9701CRITICALCVSS 9.8EG 9.82025-03-20
A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially …
- CVE-2024-9917MEDIUMCVSS 6.3EG 6.32024-10-13
A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization…
- CVE-2024-9953MEDIUMCVSS 4.9EG 4.92024-10-14
A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition …
- CVE-2025-0428HIGHCVSS 7.2EG 7.22025-01-22
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_p…
- CVE-2025-0429HIGHCVSS 7.2EG 7.22025-01-22
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_a…
- CVE-2025-0465HIGHCVSS 7.3EG 7.32025-01-14
A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v2/categories. The manipulation of the argument PostBody.populate leads to deserializatio…
- CVE-2025-0586HIGHCVSS 7.2EG 7.22025-01-20
The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.
- CVE-2025-0724HIGHCVSS 8.8EG 8.82025-03-22
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html func…
- CVE-2025-0734MEDIUMCVSS 4.7EG 4.72025-01-27
A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to deserialization. The attack can be initiate…
- CVE-2025-0767CRITICALCVSS 9.8EG 9.82025-02-27
WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.
- CVE-2025-0769MEDIUMCVSS 6.3EG 0.02025-02-28
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/modules/facebook/facebook-server-a sync-task.php.
- CVE-2025-0841HIGHCVSS 7.3EG 7.32025-01-29
A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initi…
- CVE-2025-0855CRITICALCVSS 9.8EG 9.82025-05-06
The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via deserialization of untrusted input in the 'import_header' function. This makes it possible for unauthenticated attacker…
- CVE-2025-0912CRITICALCVSS 9.8EG 9.82025-03-04
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it …
- CVE-2025-0956HIGHCVSS 8.1EG 8.12025-03-05
The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via deserialization of untrusted input from the 'raccookie_guest_email' cookie. This makes it po…
- CVE-2025-0974MEDIUMCVSS 5.0EG 5.02025-02-03
A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. …
- CVE-2025-0994HIGHCVSS 8.8EG 9.0⚠ KEV2025-02-06
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack agai…
- CVE-2025-10035CRITICALCVSS 10.0EG 10.0⚠ KEV2025-09-18
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- CVE-2025-10164HIGHCVSS 7.3EG 7.32025-09-09
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. T…
- CVE-2025-10252LOWCVSS 3.1EG 3.12025-09-11
A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The a…
- CVE-2025-10363CRITICALCVSS 10.0EG 0.02025-10-06
Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and is fixed in version 11.2.12.00
- CVE-2025-10433MEDIUMCVSS 6.3EG 6.32025-09-15
A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the file /admin/api/workspace/default/tool/debug. Executing manipulation of the argument code can lead to deserialization. …
- CVE-2025-10492CRITICALCVSS 9.8EG 9.82025-09-16
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
- CVE-2025-10768MEDIUMCVSS 6.3EG 6.32025-09-21
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. Th…
- CVE-2025-10769MEDIUMCVSS 6.3EG 6.32025-09-21
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The at…
- CVE-2025-1077CRITICALCVSS 9.5EG 0.02025-02-07
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in spe…
- CVE-2025-10770MEDIUMCVSS 6.3EG 6.32025-09-21
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Rem…
- CVE-2025-10771MEDIUMCVSS 6.3EG 6.32025-09-21
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteS…
- CVE-2025-10950MEDIUMCVSS 6.3EG 6.32025-09-25
A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This manipulation of the argument data c…
- CVE-2025-10965MEDIUMCVSS 6.3EG 6.32025-09-25
A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/components/deploy/relay/server.py. Such manipulation leads to deserialization. The attack ca…
- CVE-2025-10974MEDIUMCVSS 6.3EG 6.32025-09-25
A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of the file /calculate of the component Endpoint. Such manipulation of the argument body_parts/…
- CVE-2025-10975MEDIUMCVSS 6.3EG 6.32025-09-25
A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.robot.bridge.reasoning_server::run_reasoning_server of the file experiments/robot/bridge/reas…
- CVE-2025-1113MEDIUMCVSS 6.3EG 6.32025-02-07
A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The …
- CVE-2025-11135HIGHCVSS 7.3EG 7.32025-09-29
A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the function loadLanguage of the file classes/class.database.php of the component Cookie Handler. …
- CVE-2025-11157HIGHCVSS 7.8EG 7.82026-01-01
A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability a…
- CVE-2025-11273MEDIUMCVSS 6.3EG 6.32025-10-04
A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL results in deserialization. The atta…
- CVE-2025-11345MEDIUMCVSS 5.5EG 5.52025-10-06
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to ve…
- CVE-2025-11346MEDIUMCVSS 6.3EG 6.32025-10-06
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch t…
- CVE-2025-11367CRITICALCVSS 9.8EG 9.82025-11-12
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
- CVE-2025-11622HIGHCVSS 7.8EG 7.82025-10-13
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.
- CVE-2025-1177MEDIUMCVSS 6.3EG 6.32025-02-11
A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/Control/Admin/Linkage.php. The manipulation leads to deserialization. It is possible to la…
- CVE-2025-1186MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects unknown code of the file /Control/Api/Api.php. The manipulation of the argument thumb leads to deserialization. The att…
- CVE-2025-11938MEDIUMCVSS 5.6EG 5.62025-10-19
A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may…
- CVE-2025-11993HIGHCVSS 8.8EG 8.82026-05-29
The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deseria…
- CVE-2025-12058MEDIUMCVSS 5.9EG 0.02025-10-29
The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way …
- CVE-2025-12099HIGHCVSS 7.2EG 7.22025-11-08
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.8 via deserialization of untrusted input in the 'import_all_cours…
- CVE-2025-12305MEDIUMCVSS 6.3EG 6.32025-10-27
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. The manipulation results in deserializatio…
- CVE-2025-12844HIGHCVSS 7.1EG 7.12025-11-13
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVision…
- CVE-2025-13081MEDIUMCVSS 5.9EG 5.92025-11-18
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 bef…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →