CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

976
Total CVEs
476
Critical
444
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 56
2 Microsoft 35
3 Solarwinds 19
4 Ibm 15
5 Adobe 14
6 Givewp 9
7 Ivanti 9
8 Google 8
9 Huawei 8
10 Debian 8

All Deserialization of Untrusted Data CVEs (976)

CVE-2026-20131
10.0

This critical vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to execute arbitrary Java code with roo...

Mar 4, 2026
CVE-2026-25632
10.0

CVE-2026-25632 is a critical remote code execution vulnerability in EPyT-Flow's REST API. Attackers can send malicious JSON payloads that trigger dyna...

Feb 6, 2026
CVE-2025-55182
KEV EPSS 60.9% 10.0

A critical pre-authentication remote code execution vulnerability exists in React Server Components where unsafe deserialization of HTTP payloads allo...

Dec 3, 2025
CVE-2025-58384
10.0

This vulnerability allows remote attackers to execute arbitrary code on DOXENSE WATCHDOC systems by exploiting insecure deserialization in the .NET Re...

Sep 26, 2025
CVE-2025-42944
10.0

This CVE describes a critical deserialization vulnerability in SAP NetWeaver's RMI-P4 module that allows unauthenticated attackers to execute arbitrar...

Sep 9, 2025
CVE-2025-48200
10.0

This critical vulnerability in the sr_feuser_register TYPO3 extension allows unauthenticated attackers to execute arbitrary code on affected systems. ...

May 21, 2025
CVE-2025-30012
10.0

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands as SAP Administrator on SAP SRM systems using the d...

May 13, 2025
CVE-2025-32444
10.0

This vulnerability allows remote code execution on vLLM instances using mooncake integration via insecure pickle deserialization over ZeroMQ sockets. ...

Apr 30, 2025
CVE-2024-44102
10.0

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Siemens TeleControl Server Basic system...

Nov 12, 2024
CVE-2024-8353
10.0

This vulnerability allows unauthenticated attackers to perform PHP object injection in the GiveWP WordPress plugin, leading to arbitrary file deletion...

Sep 28, 2024
CVE-2024-5932
10.0

The GiveWP WordPress plugin is vulnerable to PHP object injection via the 'give_title' parameter, allowing unauthenticated attackers to execute arbitr...

Aug 20, 2024
CVE-2024-37099
10.0

CVE-2024-37099 is an unauthenticated PHP object injection vulnerability in the GiveWP WordPress plugin. Attackers can exploit deserialization of untru...

Aug 19, 2024
CVE-2024-30225
10.0

CVE-2024-30225 is an unauthenticated PHP object injection vulnerability in the WP Migrate WordPress plugin. It allows remote attackers to execute arbi...

Mar 28, 2024
CVE-2024-25100
10.0

This vulnerability allows unauthenticated attackers to inject malicious PHP objects via deserialization in the WP Swings Coupon Referral Program WordP...

Feb 12, 2024
CVE-2023-49778
10.0

This CVE describes an unauthenticated PHP object injection vulnerability in the WordPress Sayfa Sayac plugin. Attackers can exploit deserialization of...

Dec 21, 2023
CVE-2023-49772
10.0

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code through deserialization of untrusted data in the Genesis Simple Love...

Dec 20, 2023
CVE-2023-46604
10.0

CVE-2023-46604 is a critical remote code execution vulnerability in Apache ActiveMQ's Java OpenWire protocol marshaller. It allows remote attackers wi...

Oct 27, 2023
CVE-2021-27460
10.0

CVE-2021-27460 is a critical deserialization vulnerability in Rockwell Automation FactoryTalk AssetCentre that allows remote unauthenticated attackers...

Mar 23, 2022
CVE-2019-19810
10.0

CVE-2019-19810 is a critical Java deserialization vulnerability in Zoom Call Recording 6.3.1 from Eleveo that allows remote unauthenticated attackers ...

Oct 28, 2021
CVE-2021-37181
10.0

This vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems by exploiting insecure deserialization in Siemens Ce...

Sep 14, 2021
CVE-2025-49113
EPSS 91.8% 9.9

CVE-2025-49113 is a critical remote code execution vulnerability in Roundcube Webmail affecting authenticated users. It allows attackers to execute ar...

Jun 2, 2025
CVE-2024-37361
9.9

This vulnerability allows remote attackers to execute arbitrary code on Hitachi Vantara Pentaho Business Analytics Server by sending specially crafted...

Feb 20, 2025
CVE-2025-20124
9.9

This vulnerability allows authenticated attackers with read-only admin credentials to execute arbitrary commands as root on Cisco ISE devices via inse...

Feb 5, 2025
CVE-2024-37288
9.9

A deserialization vulnerability in Kibana allows arbitrary code execution when parsing malicious YAML documents. This only affects users who have enab...

Sep 9, 2024
CVE-2024-6327
9.9

This CVE describes a remote code execution vulnerability in Progress Telerik Report Server caused by insecure deserialization. Attackers can exploit t...

Jul 24, 2024
CVE-2024-29212
9.9

This vulnerability allows remote code execution on Veeam Service Provider Console servers through unsafe deserialization in agent communication. Attac...

May 14, 2024
CVE-2024-1800
9.9

This vulnerability allows remote attackers to execute arbitrary code on Progress Telerik Report Server through insecure deserialization. Attackers can...

Mar 20, 2024
CVE-2024-20253
9.9

This critical vulnerability in Cisco Unified Communications and Contact Center Solutions allows unauthenticated remote attackers to execute arbitrary ...

Jan 26, 2024
CVE-2023-52219
9.9

This CVE describes a PHP object injection vulnerability in the Gecka Terms Thumbnails WordPress plugin due to insecure deserialization of untrusted da...

Jan 8, 2024
CVE-2023-52182
9.9

This vulnerability allows attackers to execute arbitrary PHP code through deserialization of untrusted data in the ARI Stream Quiz WordPress plugin. I...

Dec 31, 2023
CVE-2023-51470
9.9

This vulnerability allows authenticated attackers to perform PHP object injection through deserialization of untrusted data in the Rencontre WordPress...

Dec 29, 2023
CVE-2023-30898
9.9

This CVE describes a critical deserialization vulnerability in Siemens Siveillance Video Event Server that allows authenticated remote attackers to ex...

May 9, 2023
CVE-2021-29485
9.9

This vulnerability allows remote code execution via Java deserialization attacks against Ratpack's session store. Attackers can execute arbitrary code...

Jun 29, 2021
CVE-2026-2599
9.8

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted inpu...

Mar 5, 2026
CVE-2026-3422
9.8

U-Office Force software has an insecure deserialization vulnerability that allows unauthenticated attackers to remotely execute arbitrary code on affe...

Mar 2, 2026
CVE-2025-69405
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the ThemeREX Lorem Ipsum | Books & Media ...

Feb 20, 2026
CVE-2025-69371
9.8

This CVE describes a PHP object injection vulnerability in the KindlyCare WordPress theme where untrusted data can be deserialized, potentially allowi...

Feb 20, 2026
CVE-2025-69329
9.8

This CVE describes a PHP object injection vulnerability in the Jthemes Prestige WordPress theme, caused by insecure deserialization of untrusted data....

Feb 20, 2026
CVE-2025-69301
9.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting insecure deserialization in the PhotoMe WordP...

Feb 20, 2026
CVE-2025-68541
9.8

This vulnerability in the BoldThemes Ippsum WordPress theme allows attackers to inject malicious objects through deserialization of untrusted data. It...

Feb 20, 2026
CVE-2025-67996
9.8

This CVE describes a PHP object injection vulnerability in the BoldThemes Nestin WordPress theme. Attackers can exploit insecure deserialization to ex...

Feb 20, 2026
CVE-2026-23542
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Grand Restaurant WordPress theme. Suc...

Feb 19, 2026
CVE-2026-23549
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WpEvently mage-eventpress WordPress p...

Feb 19, 2026
CVE-2026-21531
9.8

This critical vulnerability in Azure SDK allows remote code execution through deserialization of untrusted data. Attackers can exploit this over a net...

Feb 10, 2026
CVE-2025-40551
KEV EPSS 77.7% 9.8

SolarWinds Web Help Desk has an unauthenticated remote code execution vulnerability via untrusted data deserialization. Attackers can execute arbitrar...

Jan 28, 2026
CVE-2025-40553
9.8

SolarWinds Web Help Desk has an unauthenticated remote code execution vulnerability via untrusted data deserialization. Attackers can exploit this to ...

Jan 28, 2026
CVE-2026-0773
9.8

CVE-2026-0773 is a critical remote code execution vulnerability in Upsonic's Cloudpickle deserialization. Attackers can execute arbitrary code without...

Jan 23, 2026
CVE-2026-0763
9.8

CVE-2026-0763 is a critical deserialization vulnerability in GPT Academic's run_in_subprocess_wrapper_func that allows unauthenticated remote attacker...

Jan 23, 2026
CVE-2026-0764
9.8

CVE-2026-0764 is a critical deserialization vulnerability in GPT Academic's upload endpoint that allows unauthenticated remote attackers to execute ar...

Jan 23, 2026
CVE-2026-0760
9.8

CVE-2026-0760 is a critical remote code execution vulnerability in Foundation Agents MetaGPT's deserialize_message function. Attackers can exploit thi...

Jan 23, 2026

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 976 CVEs classified as CWE-502, with 476 rated critical and 444 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free