CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,008
Total CVEs
491
Critical
461
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 57
2 Microsoft 36
3 Solarwinds 19
4 Ibm 18
5 Debian 16
6 Adobe 14
7 Oracle 14
8 Netapp 11
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,008)

CVE-2025-52827
8.8

A deserialization vulnerability in the uxper Nuss WordPress theme allows attackers to inject malicious objects by manipulating serialized data. This a...

Jun 27, 2025
CVE-2025-47166
8.8

CVE-2025-47166 is a deserialization vulnerability in Microsoft Office SharePoint that allows authenticated attackers to execute arbitrary code remotel...

Jun 10, 2025
CVE-2025-27818
8.8

This CVE describes a Java deserialization vulnerability in Apache Kafka Connect that allows authenticated operators with configuration privileges to e...

Jun 10, 2025
CVE-2025-39358
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP Posts Carousel WordPress plugin. S...

Jun 6, 2025
CVE-2025-23254
8.8

This vulnerability in NVIDIA TensorRT-LLM allows attackers with local access to the TRTLLM server to exploit a data validation issue, potentially lead...

May 1, 2025
CVE-2025-39527
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Rating by BestWebSoft WordPress plugi...

Apr 17, 2025
CVE-2025-32662
8.8

A deserialization vulnerability in the Stylemix uListing WordPress plugin allows attackers to inject malicious objects by processing untrusted data. T...

Apr 17, 2025
CVE-2025-31932
8.8

A deserialization vulnerability in BizRobo! Management Console allows remote attackers to execute arbitrary code by sending maliciously crafted data. ...

Apr 11, 2025
CVE-2025-32144
8.8

A PHP object injection vulnerability in the Job Board Manager WordPress plugin allows attackers to execute arbitrary code through deserialization of u...

Apr 11, 2025
CVE-2025-30892
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WpTravelly WordPress plugin. Successf...

Apr 1, 2025
CVE-2025-27130
8.8

Welcart e-Commerce versions 2.11.6 and earlier contain an untrusted data deserialization vulnerability that allows remote unauthenticated attackers to...

Apr 1, 2025
CVE-2025-31129
8.8

This vulnerability in Jooby's pac4j SessionStoreImpl module allows remote code execution through insecure deserialization of untrusted session data. A...

Mar 31, 2025
CVE-2025-0724
8.8

The ProfileGrid WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input, allowing authenticated attackers with S...

Mar 22, 2025
CVE-2025-23120
EPSS 25.8% 8.8

This vulnerability allows remote code execution (RCE) for domain users in Veeam Backup & Replication. Attackers can execute arbitrary code with domain...

Mar 20, 2025
CVE-2024-11039
8.8

This vulnerability allows remote attackers to execute arbitrary commands on systems running vulnerable versions of binary-husky/gpt_academic by exploi...

Mar 20, 2025
CVE-2025-26921
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Booking and Rental Manager WordPress ...

Mar 15, 2025
CVE-2025-26967
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Events Calendar for GeoDirectory Word...

Mar 3, 2025
CVE-2024-28777
8.8

IBM Cognos Controller and IBM Controller contain an unrestricted deserialization vulnerability that allows authenticated users to execute arbitrary co...

Feb 19, 2025
CVE-2025-0994
KEV EPSS 77.8% 8.8

This vulnerability allows authenticated users to execute arbitrary code on Trimble Cityworks servers via deserialization attacks. It affects organizat...

Feb 6, 2025
CVE-2025-24661
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Taxi Booking Manager for WooCommerce ...

Feb 3, 2025
CVE-2024-31903
EPSS 17.1% 8.8

This vulnerability allows attackers on the local network to execute arbitrary code on IBM Sterling B2B Integrator systems by exploiting insecure deser...

Jan 22, 2025
CVE-2024-10936
EPSS 29.1% 8.8

The String Locator WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input, allowing unauthenticated attacke...

Jan 21, 2025
CVE-2022-45185
8.8

SuiteCRM 7.12.7 contains an authenticated file upload vulnerability that allows authenticated users to upload malicious files. When combined with inse...

Jan 7, 2025
CVE-2024-55555
EPSS 33.3% 8.8

CVE-2024-55555 is an unauthenticated remote code execution vulnerability in Invoice Ninja that allows attackers who know the APP_KEY to execute arbitr...

Jan 7, 2025
CVE-2024-10957
8.8

The UpdraftPlus WordPress backup plugin contains a PHP object injection vulnerability in versions 1.23.8 through 1.24.11. Unauthenticated attackers ca...

Jan 4, 2025
CVE-2024-10932
8.8

The Backup Migration plugin for WordPress is vulnerable to PHP object injection via insecure deserialization, allowing unauthenticated attackers to ex...

Jan 4, 2025
CVE-2024-11947
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges on GFI Archiver installations. The flaw exis...

Dec 12, 2024
CVE-2024-53247
8.8

This vulnerability allows low-privileged users without admin or power roles to execute arbitrary code remotely on affected Splunk systems. It affects ...

Dec 10, 2024
CVE-2024-11501
8.8

The Gallery WordPress plugin up to version 1.3 contains a PHP object injection vulnerability via the wd_gallery_$id parameter. This allows authenticat...

Dec 7, 2024
CVE-2024-10587
8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform PHP object injection via deserialization of...

Dec 4, 2024
CVE-2024-11394
8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into loading malicious model files in Hugging Face Transformers...

Nov 22, 2024
CVE-2024-11392
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Hugging Face Transformers with MobileVi...

Nov 22, 2024
CVE-2024-52445
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the QRMenu Restaurant QR Menu Lite WordPr...

Nov 20, 2024
CVE-2024-10962
8.8

The WPvivid WordPress plugin is vulnerable to PHP object injection via insecure deserialization in staging site functions. Unauthenticated attackers c...

Nov 14, 2024
CVE-2024-50416
8.8

This vulnerability allows attackers to inject malicious objects through untrusted data deserialization in the WPC Shop as a Customer for WooCommerce W...

Oct 28, 2024
CVE-2024-49227
8.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Free Stock Photos Foter WordPress plu...

Oct 16, 2024
CVE-2024-45733
8.8

In Splunk Enterprise for Windows, low-privileged users without admin or power roles can achieve remote code execution due to insecure session storage....

Oct 14, 2024
CVE-2024-7432
8.8

The Unseen Blog WordPress theme is vulnerable to PHP Object Injection through deserialization of untrusted input. This allows authenticated attackers ...

Oct 1, 2024
CVE-2024-7434
8.8

The UltraPress WordPress theme is vulnerable to PHP object injection through deserialization of untrusted input. This allows authenticated attackers w...

Oct 1, 2024
CVE-2024-8922
8.8

This vulnerability allows authenticated attackers with Author-level WordPress access to perform PHP object injection via deserialization of untrusted ...

Sep 27, 2024
CVE-2024-42323
8.8

This vulnerability allows authorized attackers to execute arbitrary code on Apache HertzBeat servers by exploiting insecure deserialization in SnakeYa...

Sep 21, 2024
CVE-2024-45852
8.8

CVE-2024-45852 is a deserialization vulnerability in MindsDB that allows remote code execution when malicious models are uploaded. Attackers can execu...

Sep 12, 2024
CVE-2024-38018
8.8

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by exploiting insecure deserialization. It affects...

Sep 10, 2024
CVE-2024-42363
8.8

This vulnerability allows remote code execution through unsafe YAML deserialization in the Kubernetes plugin of the Samson deployment tool. Attackers ...

Aug 20, 2024
CVE-2024-6152
8.8

The Flipbox Builder WordPress plugin is vulnerable to PHP Object Injection via insecure deserialization, allowing authenticated attackers with Contrib...

Jul 27, 2024
CVE-2023-46801
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on Apache Linkis servers by exploiting Java deserialization when adding My...

Jul 15, 2024
CVE-2024-5724
8.8

The Photo Video Gallery Master WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'PVGM_all_photos_d...

Jun 19, 2024
CVE-2024-36528
8.8

This vulnerability allows remote code execution through insecure deserialization in NukeViet and NukeViet-eGov admin interfaces. Attackers can exploit...

Jun 10, 2024
CVE-2024-37058
8.8

This vulnerability in MLflow allows remote code execution when users interact with maliciously uploaded Langchain AgentExecutor models. Attackers can ...

Jun 4, 2024
CVE-2024-37060
8.8

This vulnerability in MLflow allows remote code execution when deserializing untrusted data from malicious Recipes. It affects MLflow versions 1.27.0 ...

Jun 4, 2024

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,008 CVEs classified as CWE-502, with 491 rated critical and 461 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free