CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 39 of 61
- CVE-2025-28970CRITICALCVSS 9.8EG 9.82025-06-27
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects WP Optimize By xTraffic: from n/a through <= 5.1.6.
- CVE-2025-29310CRITICALCVSS 9.8EG 9.82025-03-24
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.
- CVE-2025-2939MEDIUMCVSS 5.6EG 5.62025-06-03
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it p…
- CVE-2025-29783CRITICALCVSS 9.0EG 9.02025-03-19
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute r…
- CVE-2025-29793HIGHCVSS 7.2EG 7.22025-04-08
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-29807HIGHCVSS 8.7EG 8.72025-03-21
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
- CVE-2025-29953CRITICALCVSS 9.8EG 9.82025-04-18
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unb…
- CVE-2025-30012CRITICALCVSS 10.0EG 10.02025-05-13
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then…
- CVE-2025-30023CRITICALCVSS 9.0EG 9.02025-07-11
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
- CVE-2025-30025HIGHCVSS 7.8EG 7.82025-07-11
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
- CVE-2025-30065CRITICALCVSS 9.8EG 9.82025-04-01
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
- CVE-2025-30160HIGHCVSS 7.5EG 7.52025-03-20
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bo…
- CVE-2025-30165HIGHCVSS 8.0EG 8.02025-05-06
vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and co…
- CVE-2025-30284HIGHCVSS 8.4EG 8.42025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could l…
- CVE-2025-30285HIGHCVSS 8.4EG 8.42025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could l…
- CVE-2025-30378HIGHCVSS 7.0EG 7.02025-05-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- CVE-2025-30382HIGHCVSS 7.8EG 7.82025-05-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- CVE-2025-30384HIGHCVSS 7.4EG 7.42025-05-13
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- CVE-2025-30618CRITICALCVSS 9.8EG 9.82025-06-17
Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows Object Injection.This issue affects Rapyd Payment Extension for WooCommerce: from n/a through <= 1.2.0.
- CVE-2025-30761MEDIUMCVSS 5.9EG 5.92025-07-15
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and 11.0.27; Oracle GraalVM Enterprise Ed…
- CVE-2025-30773HIGHCVSS 7.2EG 7.22025-03-27
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
- CVE-2025-30889HIGHCVSS 8.8EG 8.82025-04-03
Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: from n/a through <= 2.0.13.
- CVE-2025-30892HIGHCVSS 8.8EG 8.82025-04-01
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n/a through <= 1.8.7.
- CVE-2025-30949CRITICALCVSS 9.8EG 9.82025-07-16
Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4.
- CVE-2025-30973CRITICALCVSS 9.8EG 9.82025-07-16
Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This issue affects CoSchool LMS: from n/a through <= 1.4.3.
- CVE-2025-30985CRITICALCVSS 9.8EG 9.82025-04-15
Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.
- CVE-2025-31047HIGHCVSS 8.8EG 8.82026-01-05
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Themify Edmin: from n/a through 2.0.0.
- CVE-2025-31049CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.
- CVE-2025-31052CRITICALCVSS 9.8EG 9.82025-06-09
Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This issue affects The Fashion - Model Agency One Page Beauty Theme: from n/a through <= 1.4.4.
- CVE-2025-31069CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.
- CVE-2025-31074HIGHCVSS 8.8EG 8.82025-04-01
Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This issue affects Mobile DJ Manager: from n/a through <= 1.7.5.2.
- CVE-2025-31084CRITICALCVSS 9.8EG 9.82025-04-01
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10.
- CVE-2025-31087CRITICALCVSS 9.8EG 9.82025-04-01
Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows Object Injection.This issue affects Multiple Shipping A…
- CVE-2025-31103HIGHCVSS 7.5EG 7.52025-03-31
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the ser…
- CVE-2025-31129HIGHCVSS 8.8EG 8.82025-03-31
Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).
- CVE-2025-31175HIGHCVSS 8.4EG 8.42025-04-07
Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.
- CVE-2025-31396CRITICALCVSS 9.8EG 9.82025-06-09
Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Business WordPress Theme: from n/a through 1.5.
- CVE-2025-31398CRITICALCVSS 9.8EG 9.82025-06-09
Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative MultiPurpose: from n/a through 1.7.
- CVE-2025-31422HIGHCVSS 8.8EG 8.82025-07-16
Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme visual-arts allows Object Injection.This issue affects Visual Art | Gallery WordPress Theme: from n/a through <= 2.4.
- CVE-2025-31423CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affects Umberto: from n/a through <= 1.2.8.
- CVE-2025-31429CRITICALCVSS 9.8EG 9.82025-06-09
Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3…
- CVE-2025-31430CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
- CVE-2025-31612CRITICALCVSS 9.8EG 9.82025-04-01
Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll cbxpoll allows Object Injection.This issue affects CBX Poll: from n/a through <= 2.0.4.
- CVE-2025-3162MEDIUMCVSS 5.3EG 5.32025-04-03
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation le…
- CVE-2025-31631CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue affects Fish House: from n/a through <= 1.2.7.
- CVE-2025-31634HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue affects Insurance: from n/a through <= 3.5.
- CVE-2025-3165MEDIUMCVSS 5.3EG 5.32025-04-03
A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend.py. The manipulation of the argument ckpt_path/quant_ckpt_dir leads to deserialization. A…
- CVE-2025-31919CRITICALCVSS 9.8EG 9.82025-06-17
Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7.
- CVE-2025-31924HIGHCVSS 8.8EG 8.82025-05-23
Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/a through <= 2.5.
- CVE-2025-31927CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola: from n/a through 1.6.5.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →