CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 38 of 61
- CVE-2025-24447CRITICALCVSS 9.1EG 9.12025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confi…
- CVE-2025-24601CRITICALCVSS 9.8EG 9.82025-01-27
Deserialization of Untrusted Data vulnerability in ThimPress FundPress fundpress allows Object Injection.This issue affects FundPress: from n/a through <= 2.0.6.
- CVE-2025-24661CRITICALCVSS 8.8EG 9.82025-02-03
Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Injection.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.1.8.
- CVE-2025-24671CRITICALCVSS 9.8EG 9.82025-01-27
Deserialization of Untrusted Data vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Object Injection.This issue affects Save as PDF: from n/a through <= 4.4.0.
- CVE-2025-24777HIGHCVSS 8.8EG 8.82025-07-16
Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7.
- CVE-2025-24779HIGHCVSS 8.8EG 8.82025-07-16
Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: from n/a through < 2.9.3.
- CVE-2025-24794MEDIUMCVSS 6.7EG 6.72025-01-29
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector f…
- CVE-2025-24813CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-10
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache…
- CVE-2025-2485HIGHCVSS 7.5EG 7.52025-03-28
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' fu…
- CVE-2025-24919HIGHCVSS 8.1EG 8.12025-06-13
A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command ca…
- CVE-2025-25034CRITICALCVSS 9.3EG 9.32025-06-20
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to s…
- CVE-2025-2566CRITICALCVSS 9.3EG 9.32025-06-24
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.
- CVE-2025-25691MEDIUMCVSS 6.5EG 6.52025-07-30
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2025-25692MEDIUMCVSS 6.5EG 6.52025-07-30
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2025-25940CRITICALCVSS 9.8EG 9.82025-03-10
VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.
- CVE-2025-2622MEDIUMCVSS 6.3EG 6.32025-03-22
A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipu…
- CVE-2025-26397HIGHCVSS 7.8EG 7.82025-07-24
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protec…
- CVE-2025-26399CRITICALCVSS 9.8EG 9.8⚠ KEV2025-09-23
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is…
- CVE-2025-26763CRITICALCVSS 9.8EG 9.82025-02-22
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through <= 3.94.0.
- CVE-2025-26866HIGHCVSS 8.8EG 8.82025-12-12
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict clas…
- CVE-2025-26873CRITICALCVSS 9.0EG 9.02025-03-27
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
- CVE-2025-26885HIGHCVSS 7.2EG 7.22025-03-03
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
- CVE-2025-2689MEDIUMCVSS 6.3EG 6.32025-03-24
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserial…
- CVE-2025-2690MEDIUMCVSS 6.3EG 6.32025-03-24
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is poss…
- CVE-2025-26900CRITICALCVSS 9.8EG 9.82025-02-25
Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue affects Flexmls® IDX: from n/a through <= 3.14.27.
- CVE-2025-26921HIGHCVSS 8.8EG 8.82025-03-15
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.2.6.
- CVE-2025-26967HIGHCVSS 8.8EG 8.82025-03-03
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14.
- CVE-2025-26999HIGHCVSS 8.8EG 8.82025-03-03
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.3.
- CVE-2025-27130HIGHCVSS 8.8EG 8.82025-04-01
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites create…
- CVE-2025-27203CRITICALCVSS 9.6EG 9.62025-07-08
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is cha…
- CVE-2025-27286CRITICALCVSS 9.8EG 9.82025-04-17
Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injection.This issue affects Saoshyant Slider: from n/a through <= 3.0.
- CVE-2025-27287CRITICALCVSS 9.8EG 9.82025-04-17
Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS Quiz: from n/a through <= 2.0.5.
- CVE-2025-27300HIGHCVSS 7.2EG 7.22025-02-24
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1.
- CVE-2025-27301HIGHCVSS 7.2EG 7.22025-02-24
Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-manager allows Object Injection.This issue affects NHR Options Table Manager: from n/a through <= 1.1.2.
- CVE-2025-27511HIGHCVSS 7.2EG 7.22026-06-11
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url lea…
- CVE-2025-27520CRITICALCVSS 9.8EG 9.82025-04-04
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been identified in the latest version (v1.4.2) of…
- CVE-2025-27522MEDIUMCVSS 6.5EG 6.52025-05-28
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache In…
- CVE-2025-27526MEDIUMCVSS 6.5EG 6.52025-05-28
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to up…
- CVE-2025-27528CRITICALCVSS 9.1EG 9.12025-05-28
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary f…
- CVE-2025-27531CRITICALCVSS 9.8EG 9.82025-06-06
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. …
- CVE-2025-27778CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of t…
- CVE-2025-27779CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a…
- CVE-2025-27780CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in model_information.py takes user-supplied input (e.g. a path to a model) and pass that valu…
- CVE-2025-27781CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take user-supplied input (e.g. a path to a model) a…
- CVE-2025-27816CRITICALCVSS 9.8EG 9.82025-03-07
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows Pl…
- CVE-2025-27818HIGHCVSS 8.8EG 8.82025-06-10
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka clien…
- CVE-2025-27819HIGHCVSS 7.5EG 7.52025-06-10
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnera…
- CVE-2025-27925HIGHCVSS 8.5EG 8.52025-03-10
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
- CVE-2025-2855MEDIUMCVSS 4.7EG 4.72025-03-27
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserializ…
- CVE-2025-28961CRITICALCVSS 9.8EG 9.82025-07-16
Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Shortener: from n/a through <= 3.0.7.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →