CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 63 of 66
- CVE-2026-61771HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61772HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61773HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61774HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61775HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61776HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61777HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61778HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-61779HIGHCVSS 7.8EG 7.82026-09-01
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- CVE-2026-62103CRITICALCVSS 9.8EG 9.82026-09-11
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
- CVE-2026-62105CRITICALCVSS 9.8EG 9.82026-09-11
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
- CVE-2026-62107HIGHCVSS 8.8EG 8.82026-09-11
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
- CVE-2026-62263CRITICALCVSS 9.2EG 9.22026-07-24
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an…
- CVE-2026-62912MEDIUMCVSS 6.5EG 6.52026-08-11
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- CVE-2026-62997HIGHCVSS 7.7EG 7.72026-09-16
Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-sup…
- CVE-2026-63077CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-27
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVE-2026-63514HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-63516MEDIUMCVSS 6.5EG 6.52026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-63767CRITICALCVSS 9.8EG 9.82026-07-20
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ…
- CVE-2026-64606CRITICALCVSS 9.8EG 9.82026-07-21
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users a…
- CVE-2026-64608CRITICALCVSS 9.8EG 9.82026-07-21
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input w…
- CVE-2026-64901HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65493HIGHCVSS 7.5EG 7.52026-07-23
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
- CVE-2026-65497HIGHCVSS 7.2EG 7.22026-07-23
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
- CVE-2026-65549HIGHCVSS 7.2EG 7.22026-08-06
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
- CVE-2026-65552CRITICALCVSS 9.8EG 9.82026-08-06
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
- CVE-2026-65556CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
- CVE-2026-65571CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
- CVE-2026-65572CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
- CVE-2026-65573CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
- CVE-2026-65574CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
- CVE-2026-65575CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
- CVE-2026-65576CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
- CVE-2026-65577CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
- CVE-2026-65578CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
- CVE-2026-65579CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
- CVE-2026-65581CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
- CVE-2026-65617HIGHCVSS 8.8EG 8.82026-07-27
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
- CVE-2026-65658HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65663HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65665HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65772HIGHCVSS 8.8EG 8.82026-09-08
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
- CVE-2026-65815HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- CVE-2026-65883CRITICALCVSS 9.8EG 9.82026-07-29
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
- CVE-2026-66256HIGHCVSS 7.2EG 7.22026-08-13
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger …
- CVE-2026-66583CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
- CVE-2026-66620HIGHCVSS 7.2EG 7.22026-08-18
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
- CVE-2026-66650CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- CVE-2026-66672CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
- CVE-2026-66713CRITICALCVSS 9.8EG 9.82026-07-28
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) a…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →