CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,011 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 53 of 61
- CVE-2026-25030CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.
- CVE-2026-25031CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.
- CVE-2026-25032CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.
- CVE-2026-25166HIGHCVSS 7.8EG 7.82026-03-10
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
- CVE-2026-25204HIGHCVSS 7.5EG 7.52026-04-13
Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. This issue affects escarogt prior to commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335
- CVE-2026-25316HIGHCVSS 7.2EG 7.22026-02-19
Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19.
- CVE-2026-25358HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2.
- CVE-2026-25359HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.
- CVE-2026-25360HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.
- CVE-2026-25400HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.
- CVE-2026-25429CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.
- CVE-2026-25445HIGHCVSS 8.8EG 8.82026-03-19
Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.
- CVE-2026-25449CRITICALCVSS 9.8EG 9.82026-03-18
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.
- CVE-2026-25524HIGHCVSS 8.1EG 8.12026-04-20
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions su…
- CVE-2026-2555MEDIUMCVSS 7.5EG 5.02026-02-16
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generati…
- CVE-2026-25550CRITICALCVSS 9.8EG 9.82026-06-04
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singlet…
- CVE-2026-25551HIGHCVSS 7.8EG 7.82026-06-04
Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on T…
- CVE-2026-25614HIGHCVSS 7.5EG 7.52026-02-03
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
- CVE-2026-25615HIGHCVSS 7.2EG 7.22026-02-03
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
- CVE-2026-25632CRITICALCVSS 10.0EG 10.02026-02-06
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a cust…
- CVE-2026-25747HIGHCVSS 8.8EG 8.82026-02-23
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without app…
- CVE-2026-25769CRITICALCVSS 9.1EG 9.12026-03-17
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments u…
- CVE-2026-25873CRITICALCVSS 9.8EG 9.82026-03-18
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure p…
- CVE-2026-25874CRITICALCVSS 9.8EG 9.82026-04-23
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot …
- CVE-2026-25917HIGHCVSS 7.2EG 7.22026-04-18
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. U…
- CVE-2026-25923CRITICALCVSS 9.1EG 9.12026-02-09
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a mali…
- CVE-2026-25925HIGHCVSS 7.8EG 7.82026-02-09
PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts t…
- CVE-2026-2599CRITICALCVSS 9.8EG 9.82026-03-05
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This ma…
- CVE-2026-26114HIGHCVSS 8.8EG 8.82026-03-10
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-26142CRITICALCVSS 9.8EG 9.82026-06-09
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
- CVE-2026-26208HIGHCVSS 7.8EG 7.82026-02-13
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newto…
- CVE-2026-26210CRITICALCVSS 9.8EG 9.82026-04-23
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming mess…
- CVE-2026-26215CRITICALCVSS 9.3EG 9.32026-02-11
manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{met…
- CVE-2026-26220CRITICALCVSS 9.3EG 9.32026-02-17
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directl…
- CVE-2026-26221CRITICALCVSS 9.8EG 9.82026-02-13
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP chann…
- CVE-2026-26222CRITICALCVSS 9.8EG 9.82026-02-24
Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require auth…
- CVE-2026-2626HIGHCVSS 8.1EG 8.12026-03-11
The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due …
- CVE-2026-26333CRITICALCVSS 10.0EG 10.02026-02-13
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SO…
- CVE-2026-26978HIGHCVSS 8.6EG 8.62026-05-18
FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. D…
- CVE-2026-27045HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affects WooCommerce Infinite Scroll: from n/a through <= 1.6.2.
- CVE-2026-27053CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
- CVE-2026-27060HIGHCVSS 8.8EG 8.82026-07-02
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
- CVE-2026-27082CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.
- CVE-2026-27083CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.
- CVE-2026-27084CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.
- CVE-2026-27095CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n…
- CVE-2026-27096HIGHCVSS 8.1EG 8.12026-03-19
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through 1.3.
- CVE-2026-27098HIGHCVSS 8.1EG 8.12026-03-05
Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through <= 1.2.2.
- CVE-2026-27172HIGHCVSS 8.8EG 8.82026-04-27
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectIn…
- CVE-2026-27206HIGHCVSS 8.1EG 8.12026-02-21
Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any class spe…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →