CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 57 of 66
- CVE-2026-34202HIGHCVSS 7.5EG 7.52026-03-31
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (…
- CVE-2026-3422CRITICALCVSS 9.8EG 9.82026-03-02
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
- CVE-2026-3452HIGHCVSS 7.2EG 7.22026-03-04
Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized…
- CVE-2026-34615CRITICALCVSS 9.3EG 9.32026-04-14
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabili…
- CVE-2026-34659CRITICALCVSS 9.6EG 9.62026-05-12
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul…
- CVE-2026-34838CRITICALCVSS 9.9EG 9.92026-04-02
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settin…
- CVE-2026-34877CRITICALCVSS 9.8EG 9.82026-04-02
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corr…
- CVE-2026-34993HIGHCVSS 7.3EG 7.32026-06-02
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doin…
- CVE-2026-35171CRITICALCVSS 9.8EG 9.82026-04-06
Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration s…
- CVE-2026-35300CRITICALCVSS 9.8EG 9.82026-06-17
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticat…
- CVE-2026-35337HIGHCVSS 8.8EG 8.82026-04-13
Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob usin…
- CVE-2026-35439HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-35464HIGHCVSS 7.5EG 7.52026-04-07
pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in t…
- CVE-2026-35502MEDIUMCVSS 4.6EG 4.62026-08-11
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined wit…
- CVE-2026-35537HIGHCVSS 7.5EG 7.52026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
- CVE-2026-37552HIGHCVSS 8.4EG 8.42026-05-01
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_user_…
- CVE-2026-37579HIGHCVSS 7.3EG 7.32026-05-28
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component
- CVE-2026-38950HIGHCVSS 7.8EG 7.82026-06-01
An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.
- CVE-2026-39006CRITICALCVSS 9.8EG 9.82026-06-15
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- CVE-2026-39253HIGHCVSS 8.1EG 8.12026-06-23
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
- CVE-2026-39324CRITICALCVSS 9.8EG 9.82026-04-07
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls ba…
- CVE-2026-39434HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
- CVE-2026-39442HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
- CVE-2026-39443HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
- CVE-2026-39445HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
- CVE-2026-39446HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.
- CVE-2026-39467HIGHCVSS 7.2EG 7.22026-04-21
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
- CVE-2026-39471HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
- CVE-2026-39472HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
- CVE-2026-39474HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
- CVE-2026-39478HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
- CVE-2026-39481HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
- CVE-2026-39498HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
- CVE-2026-39499HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
- CVE-2026-39529CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- CVE-2026-39532HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
- CVE-2026-39539HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
- CVE-2026-39545HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
- CVE-2026-39550HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.
- CVE-2026-39551HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.
- CVE-2026-39554HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
- CVE-2026-39555HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.
- CVE-2026-39556HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
- CVE-2026-39557HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
- CVE-2026-39560HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
- CVE-2026-39567HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
- CVE-2026-39573HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
- CVE-2026-39576HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
- CVE-2026-39577MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
- CVE-2026-39578MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →