CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,011 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 56 of 61
- CVE-2026-38950HIGHCVSS 7.8EG 7.82026-06-01
An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.
- CVE-2026-39006CRITICALCVSS 9.8EG 9.82026-06-15
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- CVE-2026-39253HIGHCVSS 8.1EG 8.12026-06-23
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
- CVE-2026-39324CRITICALCVSS 9.8EG 9.82026-04-07
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls ba…
- CVE-2026-39434HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
- CVE-2026-39442HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
- CVE-2026-39443HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
- CVE-2026-39445HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
- CVE-2026-39446HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.
- CVE-2026-39467HIGHCVSS 7.2EG 7.22026-04-21
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
- CVE-2026-39471HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
- CVE-2026-39472HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
- CVE-2026-39474HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
- CVE-2026-39478HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
- CVE-2026-39481HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
- CVE-2026-39498HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
- CVE-2026-39499HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
- CVE-2026-39529CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- CVE-2026-39532HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
- CVE-2026-39539HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
- CVE-2026-39545HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
- CVE-2026-39550HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.
- CVE-2026-39551HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.
- CVE-2026-39554HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
- CVE-2026-39555HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.
- CVE-2026-39556HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
- CVE-2026-39557HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
- CVE-2026-39560HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
- CVE-2026-39567HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
- CVE-2026-39573HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
- CVE-2026-39576HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
- CVE-2026-39577MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
- CVE-2026-39578MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.
- CVE-2026-39580HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
- CVE-2026-3967MEDIUMCVSS 6.3EG 6.32026-03-12
A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableT…
- CVE-2026-39832CRITICALCVSS 9.1EG 9.12026-05-22
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of t…
- CVE-2026-39890CRITICALCVSS 9.8EG 9.82026-04-08
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an a…
- CVE-2026-40044CRITICALCVSS 9.8EG 9.82026-04-13
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cac…
- CVE-2026-40048HIGHCVSS 7.8EG 7.82026-04-27
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cas…
- CVE-2026-40357HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40368HIGHCVSS 8.0EG 8.02026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40473HIGHCVSS 8.8EG 8.82026-04-27
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a …
- CVE-2026-40725CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
- CVE-2026-40733HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
- CVE-2026-40735HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
- CVE-2026-40736HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
- CVE-2026-40738HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
- CVE-2026-40739HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
- CVE-2026-40751HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
- CVE-2026-40752HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →