CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 37 of 61
- CVE-2025-14920HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. U…
- CVE-2025-14921HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transforme…
- CVE-2025-14922HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interacti…
- CVE-2025-14924HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. Use…
- CVE-2025-14925HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is r…
- CVE-2025-14929HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Tr…
- CVE-2025-14930HIGHCVSS 7.8EG 7.82025-12-23
Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interac…
- CVE-2025-14931CRITICALCVSS 10.0EG 10.02025-12-23
Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face smolagents…
- CVE-2025-15117LOWCVSS 3.1EG 3.12025-12-28
A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer.java. Executing manipulation can lead to deserialization. The attack may be launched remote…
- CVE-2025-15222MEDIUMCVSS 5.0EG 5.02025-12-30
A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerializerTemplateForJdkUseBase64.java. Such manipulation leads to deserialization. The attack can …
- CVE-2025-15246MEDIUMCVSS 6.3EG 6.32025-12-30
A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of the component API. This manipulation of the argument argsStr causes deserialization. Remo…
- CVE-2025-15276HIGHCVSS 7.8EG 7.82025-12-31
FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to …
- CVE-2025-15348HIGHCVSS 7.8EG 7.82026-01-23
Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu ShockLine. User interaction…
- CVE-2025-15350HIGHCVSS 7.8EG 7.82026-01-23
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interacti…
- CVE-2025-15351HIGHCVSS 7.8EG 7.82026-01-23
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interacti…
- CVE-2025-15375MEDIUMCVSS 6.3EG 6.32025-12-31
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead t…
- CVE-2025-15438MEDIUMCVSS 7.2EG 4.72026-01-02
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to…
- CVE-2025-15453MEDIUMCVSS 6.3EG 6.32026-01-05
A security vulnerability has been detected in milvus up to 2.6.7. This vulnerability affects the function expr.Exec of the file pkg/util/expr/expr.go of the component HTTP Endpoint. The manipulation of the argument code leads to deserializ…
- CVE-2025-1556MEDIUMCVSS 4.7EG 4.72025-02-22
A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads to deserialization.…
- CVE-2025-15579CRITICALCVSS 9.5EG 9.52026-02-18
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory …
- CVE-2025-15610CRITICALCVSS 9.3EG 9.32026-04-15
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.
- CVE-2025-1741MEDIUMCVSS 4.7EG 4.72025-02-27
A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unknown functionality of the file src/admin/users.php of the component Admin Page. The manipulation of the argument query/…
- CVE-2025-1913HIGHCVSS 7.2EG 7.22025-03-26
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data…
- CVE-2025-1971HIGHCVSS 7.2EG 7.22025-03-22
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible …
- CVE-2025-2000CRITICALCVSS 9.8EG 9.82025-03-14
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` functi…
- CVE-2025-20124CRITICALCVSS 9.9EG 9.92025-02-05
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte …
- CVE-2025-20275MEDIUMCVSS 5.3EG 5.32025-06-04
A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device. This vulnerability is due to insecur…
- CVE-2025-20276LOWCVSS 3.8EG 3.82025-06-04
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administr…
- CVE-2025-2043MEDIUMCVSS 4.7EG 4.72025-03-06
A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads…
- CVE-2025-2105HIGHCVSS 8.1EG 8.12025-04-26
The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes i…
- CVE-2025-21364HIGHCVSS 7.8EG 7.82025-01-14
Microsoft Excel Security Feature Bypass Vulnerability
- CVE-2025-2180MEDIUMCVSS 4.8EG 4.82025-08-13
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma…
- CVE-2025-2244CRITICALCVSS 9.8EG 9.82025-04-04
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an …
- CVE-2025-2251MEDIUMCVSS 6.2EG 6.22025-04-07
A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling.…
- CVE-2025-22510HIGHCVSS 7.2EG 7.22025-01-09
Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.
- CVE-2025-22526CRITICALCVSS 9.8EG 9.82025-03-28
Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performancestats allows Object Injection.This issue affects PHP/MySQL CPU performance statistics: from n/a through <= 1.2.1.
- CVE-2025-22777CRITICALCVSS 9.8EG 9.82025-01-13
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.
- CVE-2025-23006CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-23
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote u…
- CVE-2025-23045CRITICALCVSS 9.8EG 9.82025-01-28
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function cont…
- CVE-2025-23120CRITICALCVSS 8.8EG 9.92025-03-20
A vulnerability allowing remote code execution (RCE) for domain users.
- CVE-2025-23249HIGHCVSS 7.6EG 7.62025-04-22
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
- CVE-2025-23254HIGHCVSS 8.8EG 8.82025-05-01
NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code executio…
- CVE-2025-23303HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tamper…
- CVE-2025-2332CRITICALCVSS 9.8EG 9.82025-03-27
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' fu…
- CVE-2025-2376HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The man…
- CVE-2025-23914CRITICALCVSS 9.8EG 9.82025-01-22
Deserialization of Untrusted Data vulnerability in muzaara Muzaara Google Ads Report muzaara-adwords-optimize-dashboard allows Object Injection.This issue affects Muzaara Google Ads Report: from n/a through <= 3.1.
- CVE-2025-23932CRITICALCVSS 9.8EG 9.82025-01-22
Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue affects Quick Count: from n/a through <= 3.00.
- CVE-2025-23944HIGHCVSS 8.8EG 8.82025-01-22
Deserialization of Untrusted Data vulnerability in bulktheme WOOEXIM wooexim allows Object Injection.This issue affects WOOEXIM: from n/a through <= 5.0.0.
- CVE-2025-24016CRITICALCVSS 9.9EG 9.9⚠ KEV2025-02-10
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. …
- CVE-2025-24357HIGHCVSS 7.5EG 7.52025-01-27
vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_o…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →