CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,011
Total CVEs
492
Critical
463
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 58
2 Microsoft 36
3 Solarwinds 19
4 Ibm 18
5 Debian 17
6 Oracle 16
7 Adobe 14
8 Netapp 12
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,011)

CVE-2024-37060
8.8

This vulnerability in MLflow allows remote code execution when deserializing untrusted data from malicious Recipes. It affects MLflow versions 1.27.0 ...

Jun 4, 2024
CVE-2024-37054
8.8

This vulnerability allows remote code execution through malicious PyFunc models in MLflow. Attackers can upload specially crafted models that execute ...

Jun 4, 2024
CVE-2024-37056
8.8

This vulnerability allows remote code execution through malicious ML models in MLflow. Attackers can upload specially crafted LightGBM scikit-learn mo...

Jun 4, 2024
CVE-2024-37052
8.8

This vulnerability allows remote code execution through malicious ML models in MLflow. Attackers can upload specially crafted scikit-learn models that...

Jun 4, 2024
CVE-2024-34515
8.8

CVE-2024-34515 is a PHAR deserialization vulnerability in the spatie/image-optimizer library that allows attackers to execute arbitrary code by exploi...

May 5, 2024
CVE-2023-50221
8.8

This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by exploiting insecure deserializa...

May 3, 2024
CVE-2023-50223
8.8

This vulnerability in Inductive Automation Ignition allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges by exploiti...

May 3, 2024
CVE-2023-50219
8.8

This vulnerability in Inductive Automation Ignition allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges by exploiti...

May 3, 2024
CVE-2023-39473
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code on Inductive Automation Ignition systems by exploiting insecure des...

May 3, 2024
CVE-2024-3018
8.8

This vulnerability in the Essential Addons for Elementor WordPress plugin allows authenticated attackers with author-level access or higher to perform...

Mar 30, 2024
CVE-2024-24725
8.8

This vulnerability allows remote authenticated users to execute arbitrary PHP code through deserialization attacks in Gibbon's import functionality. A...

Mar 23, 2024
CVE-2024-1685
8.8

The Social Media Share Buttons WordPress plugin is vulnerable to PHP object injection via the attachmentUrl parameter. Authenticated attackers with su...

Mar 16, 2024
CVE-2024-2006
8.8

This vulnerability allows authenticated WordPress users with contributor-level access or higher to perform PHP object injection through the Post Grid,...

Mar 13, 2024
CVE-2024-1772
8.8

The Play.ht WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the play_podcast_data post meta. This all...

Mar 13, 2024
CVE-2024-1731
8.8

The Auto Refresh Single Page WordPress plugin is vulnerable to PHP object injection via insecure deserialization of untrusted input. This allows authe...

Mar 5, 2024
CVE-2024-0825
8.8

This vulnerability in the Vimeography WordPress plugin allows authenticated attackers with contributor-level access or higher to perform PHP object in...

Mar 5, 2024
CVE-2024-20953
8.8

This vulnerability in Oracle Agile PLM allows authenticated attackers with network access to execute arbitrary code through deserialization of untrust...

Feb 17, 2024
CVE-2024-21318
8.8

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by deserializing untrusted data. It affects organi...

Jan 9, 2024
CVE-2023-6528
8.8

This vulnerability in the Slider Revolution WordPress plugin allows users with Author role or higher to execute arbitrary code through unsafe unserial...

Jan 8, 2024
CVE-2023-5235
8.8

This vulnerability in the Ovic Responsive WPBakery WordPress plugin allows attackers with subscriber-level accounts or higher to modify critical WordP...

Jan 8, 2024
CVE-2023-6730
8.8

This vulnerability in the Hugging Face Transformers library allows remote code execution through unsafe deserialization of untrusted data. Attackers c...

Dec 19, 2023
CVE-2023-35182
8.8

CVE-2023-35182 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to execute arbitrary...

Oct 19, 2023
CVE-2023-35184
8.8

CVE-2023-35184 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to execute arbitrary...

Oct 19, 2023
CVE-2023-43176
8.8

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows authenticated attackers to execute arbitrary code by uploading a specially cr...

Oct 3, 2023
CVE-2023-43268
8.8

CVE-2023-43268 is a deserialization vulnerability in Deyue Remote Vehicle Management System v1.1 that allows remote attackers to execute arbitrary cod...

Oct 2, 2023
CVE-2023-40595
8.8

This vulnerability in Splunk Enterprise allows attackers to execute arbitrary code by crafting malicious queries that exploit insecure deserialization...

Aug 30, 2023
CVE-2023-40195
8.8

This vulnerability allows authorized Airflow users with Spark hook configuration permissions to execute arbitrary code on the Airflow node by connecti...

Aug 28, 2023
CVE-2023-39106
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Nacos Spring Project. The issue stems f...

Aug 21, 2023
CVE-2023-38181
8.8

CVE-2023-38181 is a deserialization vulnerability in Microsoft Exchange Server that allows attackers to spoof email addresses and potentially execute ...

Aug 8, 2023
CVE-2023-28754
8.8

This vulnerability allows attackers with permission to modify ShardingSphere-Agent YAML configuration files to execute arbitrary code by exploiting un...

Jul 19, 2023
CVE-2023-33134
8.8

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by exploiting insecure deserialization. It affects...

Jul 11, 2023
CVE-2023-30262
8.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on MIM software's License Server and MIMpacs services via the RMI...

Jun 9, 2023
CVE-2023-33284
8.8

Marval MSM versions through 14.19.0.12476 and 15.0 contain a deserialization vulnerability (CWE-502) that allows authenticated remote attackers to exe...

Jun 7, 2023
CVE-2023-2288
8.8

The Otter WordPress plugin before version 2.2.6 contains a PHAR deserialization vulnerability that allows attackers to execute arbitrary code on vulne...

May 30, 2023
CVE-2023-2500
8.8

This vulnerability in the Go Pricing WordPress plugin allows authenticated attackers with subscriber-level permissions to perform PHP object injection...

May 25, 2023
CVE-2023-32336
8.8

IBM InfoSphere Information Server 11.7 has a remote code execution vulnerability due to insecure deserialization in an RMI service. Attackers can expl...

May 22, 2023
CVE-2023-1196
8.8

This vulnerability in Advanced Custom Fields WordPress plugins allows authenticated users with Contributor role or higher to perform PHP Object Inject...

May 2, 2023
CVE-2023-20102
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code as administrator on Cisco Secure Network Analytics devices. Attacke...

Apr 5, 2023
CVE-2023-29006
8.8

This vulnerability in the Order GLPI plugin allows authenticated users with standard interface access to execute arbitrary system commands via a craft...

Apr 5, 2023
CVE-2022-36971
8.8

This vulnerability in Ivanti Avalanche allows authenticated remote attackers to bypass authentication mechanisms and execute arbitrary code via insecu...

Mar 29, 2023
CVE-2023-27296
8.8

This vulnerability allows authenticated users of Apache InLong to execute arbitrary code through deserialization of untrusted data. It affects Apache ...

Mar 27, 2023
CVE-2023-21529
8.8

CVE-2023-21529 is a remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on ...

Feb 14, 2023
CVE-2023-25194
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on Apache Kafka Connect servers by exploiting JNDI injection through SASL ...

Feb 7, 2023
CVE-2022-2444
8.8

This vulnerability in the Visualizer WordPress plugin allows authenticated attackers with contributor-level privileges to execute arbitrary PHP code t...

Jul 18, 2022
CVE-2022-31115
8.8

This vulnerability in opensearch-ruby allows remote code execution through unsafe YAML deserialization when connecting to a malicious OpenSearch serve...

Jun 30, 2022
CVE-2022-22005
8.8

CVE-2022-22005 is a remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code o...

Feb 9, 2022
CVE-2021-39321
8.8

This vulnerability allows authenticated WordPress users with minimal privileges to perform PHP object injection attacks via a deserialization flaw in ...

Oct 21, 2021
CVE-2021-36231
8.8

CVE-2021-36231 is a deserialization vulnerability in MIK.starlight 7.9.5.24363 that allows authenticated remote attackers to execute arbitrary operati...

Aug 31, 2021
CVE-2021-21677
8.8

This vulnerability in Jenkins Code Coverage API Plugin allows attackers to execute arbitrary code on Jenkins servers by exploiting insecure deserializ...

Aug 31, 2021
CVE-2021-39132
8.8

This vulnerability allows authenticated users to upload malicious files that can execute arbitrary code on Rundeck servers. It affects all Rundeck edi...

Aug 30, 2021

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,011 CVEs classified as CWE-502, with 492 rated critical and 463 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free