CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 40 of 61
- CVE-2025-31932HIGHCVSS 8.8EG 8.82025-04-11
Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply i…
- CVE-2025-31935MEDIUMCVSS 6.2EG 6.22025-04-11
Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition.
- CVE-2025-32143HIGHCVSS 8.8EG 8.82025-04-11
Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2.3.11.
- CVE-2025-32144HIGHCVSS 8.8EG 8.82025-04-11
Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
- CVE-2025-32145HIGHCVSS 8.8EG 8.82025-04-10
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.3.6.
- CVE-2025-32283HIGHCVSS 8.8EG 8.82025-10-22
Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a through <= 3.5.
- CVE-2025-32284HIGHCVSS 8.8EG 8.82025-05-23
Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue affects Pet World: from n/a through <= 2.8.
- CVE-2025-32292CRITICALCVSS 9.8EG 9.82025-05-23
Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress jarvis allows Object Injection.This issue affects Jarvis – Night Club, Concert, Festival WordPress: from n/a through <= 1.…
- CVE-2025-32293HIGHCVSS 8.8EG 8.82025-05-23
Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consultant: from n/a through <= 2.8.
- CVE-2025-32312HIGHCVSS 7.8EG 7.82025-09-04
In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next process due to unsafe deserialization. This could lead to local escalation of privilege w…
- CVE-2025-32375CRITICALCVSS 9.8EG 9.82025-04-09
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the …
- CVE-2025-32434CRITICALCVSS 9.8EG 9.82025-04-18
PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in …
- CVE-2025-32444CRITICALCVSS 10.0EG 10.02025-04-30
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based…
- CVE-2025-3250MEDIUMCVSS 4.3EG 4.32025-04-04
A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The mani…
- CVE-2025-32568CRITICALCVSS 9.8EG 9.82025-04-11
Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects EmpikPlace for Woocommerce: from n/a through <= 1.4.3.
- CVE-2025-32569CRITICALCVSS 9.8EG 9.82025-04-11
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from n/a through <= 1.0.4.3.
- CVE-2025-32571HIGHCVSS 8.8EG 8.82025-04-17
Deserialization of Untrusted Data vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Object Injection.This issue affects TuriTop Booking System: from n/a through <= 1.0.10.
- CVE-2025-32572CRITICALCVSS 9.8EG 9.82025-04-17
Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue affects Kata Plus: from n/a through <= 1.5.3.
- CVE-2025-32607CRITICALCVSS 9.8EG 9.82025-04-11
Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBookingly: from n/a through <= 1.3.0.
- CVE-2025-32647HIGHCVSS 8.8EG 8.82025-04-17
Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.This issue affects Question Answer: from n/a through <= 1.2.73.
- CVE-2025-32658CRITICALCVSS 9.8EG 9.82025-04-17
Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects HelpGent: from n/a through <= 2.2.5.
- CVE-2025-32662HIGHCVSS 8.8EG 8.82025-04-17
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.
- CVE-2025-32686HIGHCVSS 8.8EG 8.82025-04-17
Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue affects Team Members: from n/a through <= 3.4.4.
- CVE-2025-32897CRITICALCVSS 9.8EG 9.82025-06-28
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Ap…
- CVE-2025-32927CRITICALCVSS 9.8EG 9.82025-05-19
Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This issue affects FoodBakery: from n/a through <= 3.3.
- CVE-2025-32928CRITICALCVSS 9.8EG 9.82025-05-19
Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects Altair: from n/a through <= 5.2.2.
- CVE-2025-33210CRITICALCVSS 9.0EG 9.02025-12-16
NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.
- CVE-2025-33212HIGHCVSS 7.3EG 7.32025-12-16
NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a maliciously crafted file. A successful exploit of this vulnerability might lead to code e…
- CVE-2025-33213HIGHCVSS 8.8EG 8.82025-12-09
NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, infor…
- CVE-2025-33214HIGHCVSS 8.8EG 8.82025-12-09
NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclo…
- CVE-2025-33226HIGHCVSS 7.8EG 7.82025-12-16
NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, infor…
- CVE-2025-33241HIGHCVSS 7.8EG 7.82026-02-18
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, in…
- CVE-2025-33243HIGHCVSS 7.8EG 7.82026-02-18
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information …
- CVE-2025-33244CRITICALCVSS 9.0EG 9.02026-03-24
NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this…
- CVE-2025-33245HIGHCVSS 8.8EG 8.82026-02-18
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tamp…
- CVE-2025-33247HIGHCVSS 7.8EG 7.82026-03-24
NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disc…
- CVE-2025-33248HIGHCVSS 7.8EG 7.82026-03-24
NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, …
- CVE-2025-33252HIGHCVSS 7.8EG 7.82026-02-18
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
- CVE-2025-33253HIGHCVSS 7.3EG 7.32026-02-18
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of …
- CVE-2025-33255CRITICALCVSS 9.8EG 9.82026-05-20
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, an…
- CVE-2025-34060CRITICALCVSS 10.0EG 10.02025-07-01
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The application passes a user-supplied link parameter directly to …
- CVE-2025-34067CRITICALCVSS 10.0EG 10.02025-07-02
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService…
- CVE-2025-3413MEDIUMCVSS 6.3EG 6.32025-04-08
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the file SysGeneratorController.java. The manipulat…
- CVE-2025-34153CRITICALCVSS 10.0EG 10.02025-08-13
Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031…
- CVE-2025-3425HIGHCVSS 7.3EG 7.32025-04-07
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed th…
- CVE-2025-34292CRITICALCVSS 9.4EG 9.42025-10-27
Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in …
- CVE-2025-3439CRITICALCVSS 9.8EG 9.82025-04-11
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input…
- CVE-2025-34394CRITICALCVSS 9.8EG 9.82025-12-10
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code executio…
- CVE-2025-34414CRITICALCVSS 9.3EG 9.32025-12-09
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled …
- CVE-2025-34449CRITICALCVSS 9.1EG 9.12025-12-18
Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds rea…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →