CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,013
Total CVEs
494
Critical
463
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 59
2 Microsoft 36
3 Solarwinds 19
4 Ibm 18
5 Debian 17
6 Oracle 16
7 Adobe 14
8 Netapp 12
9 Ivanti 9
10 Givewp 9

All Deserialization of Untrusted Data CVEs (1,013)

CVE-2021-21677
8.8

This vulnerability in Jenkins Code Coverage API Plugin allows attackers to execute arbitrary code on Jenkins servers by exploiting insecure deserializ...

Aug 31, 2021
CVE-2021-39132
8.8

This vulnerability allows authenticated users to upload malicious files that can execute arbitrary code on Rundeck servers. It affects all Rundeck edi...

Aug 30, 2021
CVE-2021-24579
8.8

This vulnerability in the Bold Page Builder WordPress plugin allows attackers to perform PHP Object Injection via AJAX requests. Attackers could poten...

Aug 30, 2021
CVE-2021-24307
8.8

This vulnerability allows authenticated WordPress administrators (or users with 'aioseo_tools_settings' privilege) to execute arbitrary code on the se...

May 24, 2021
CVE-2021-24280
8.8

This vulnerability in the Redirection for Contact Form 7 WordPress plugin allows any authenticated user (even low-privileged subscribers) to execute P...

May 14, 2021
CVE-2021-25151
8.8

This vulnerability allows remote attackers to execute arbitrary code on Aruba AirWave Management Platform systems by exploiting insecure deserializati...

Apr 28, 2021
CVE-2020-8884
8.8

CVE-2020-8884 allows remote authenticated users to execute arbitrary code with SYSTEM privileges on Proofpoint Insider Threat Management Windows Agent...

Jan 6, 2021
CVE-2020-26165
8.8

CVE-2020-26165 is a PHP object injection vulnerability in qdPM project management software that allows attackers to execute arbitrary code by exploiti...

Dec 31, 2020
CVE-2020-9301
8.8

This vulnerability in Spinnaker allows authenticated attackers to execute arbitrary SpEL expressions via HTTP POST requests, enabling file read/write ...

Dec 11, 2020
CVE-2024-23512
8.7

This CVE describes a PHP object injection vulnerability in the ProductX WordPress plugin that allows attackers to execute arbitrary code through deser...

Feb 12, 2024
CVE-2024-22309
8.7

This vulnerability allows unauthenticated attackers to perform PHP object injection via deserialization of untrusted data in the QuantumCloud ChatBot ...

Jan 24, 2024
CVE-2024-22284
8.7

This CVE describes a PHP object injection vulnerability in the Asgaros Forum WordPress plugin due to insecure deserialization of untrusted data. Attac...

Jan 24, 2024
CVE-2025-68665
8.6

This vulnerability allows attackers to inject malicious serialized objects into LangChain applications by exploiting improper escaping of user-control...

Dec 23, 2025
CVE-2025-60084
8.6

This vulnerability allows attackers to inject malicious objects through untrusted data deserialization in the PDF for Elementor Forms WordPress plugin...

Dec 18, 2025
CVE-2025-64512
8.6

CVE-2025-64512 is a remote code execution vulnerability in pdfminer.six where malicious PDF files can trigger deserialization of arbitrary pickle file...

Nov 10, 2025
CVE-2025-43960
8.6

CVE-2025-43960 is a PHP Object Injection vulnerability in Adminer 4.8.1 when using Monolog for logging, allowing remote unauthenticated attackers to c...

Aug 25, 2025
CVE-2025-1403
8.6

This vulnerability allows remote attackers to cause denial of service by sending maliciously crafted QPY files to Qiskit applications. The malformed s...

Feb 21, 2025
CVE-2022-1118
8.6

This vulnerability allows arbitrary code execution through insecure deserialization in Rockwell Automation engineering software. Attackers can craft m...

May 17, 2022
CVE-2025-47584
8.5

A PHP object injection vulnerability in the Photography WordPress theme allows attackers to execute arbitrary code by exploiting insecure deserializat...

Jun 6, 2025
CVE-2025-27925
8.5

CVE-2025-27925 is an insecure deserialization vulnerability in Nintex Automation that allows attackers to execute arbitrary code by sending malicious ...

Mar 10, 2025
CVE-2024-35780
8.5

This CVE describes a PHP object injection vulnerability in the Page Builder: Live Composer WordPress plugin. Attackers with contributor-level access c...

Jun 19, 2024
CVE-2024-32876
8.5

CVE-2024-32876 allows arbitrary code execution in NewPipe Android app when users import malicious backup files. The vulnerability affects all users of...

Apr 24, 2024
CVE-2024-30222
8.5

This CVE describes a PHP object injection vulnerability in the ARMember WordPress plugin, allowing attackers to execute arbitrary code through deseria...

Mar 28, 2024
CVE-2021-39150
8.5

CVE-2021-39150 is a deserialization vulnerability in XStream library that allows remote attackers to access internal resources by manipulating XML inp...

Aug 23, 2021
CVE-2025-70560
8.4

Boltz 2.0.0 contains a critical insecure deserialization vulnerability that allows arbitrary code execution when loading malicious pickle files. Attac...

Feb 3, 2026
CVE-2025-61810
8.4

This vulnerability allows attackers to execute arbitrary code on ColdFusion servers by sending malicious serialized data. It affects ColdFusion 2025.4...

Dec 10, 2025
CVE-2025-60455
8.4

CVE-2025-60455 is an unsafe deserialization vulnerability in Modular Max Serve that allows remote code execution when the experimental KVCache agent f...

Nov 18, 2025
CVE-2025-59050
8.4

This vulnerability allows a local attacker to execute arbitrary code within the Greenshot screenshot utility process by sending malicious WM_COPYDATA ...

Sep 16, 2025
CVE-2025-54886
8.4

CVE-2025-54886 is a deserialization vulnerability in the skops Python library that allows arbitrary code execution when loading models. Attackers can ...

Aug 8, 2025
CVE-2025-30285
EPSS 28.1% 8.4

This CVE describes a deserialization vulnerability in Adobe ColdFusion that allows arbitrary code execution when untrusted data is processed. Attacker...

Apr 8, 2025
CVE-2025-31175
8.4

A deserialization mismatch vulnerability in the DSoftBus module allows attackers to manipulate serialized data to potentially execute arbitrary code o...

Apr 7, 2025
CVE-2024-10095
8.4

CVE-2024-10095 is an insecure deserialization vulnerability in Progress Telerik UI for WPF that allows remote code execution. Attackers can exploit th...

Dec 16, 2024
CVE-2024-49063
8.4

CVE-2024-49063 is a remote code execution vulnerability in Microsoft/Muzic that allows attackers to execute arbitrary code on affected systems by expl...

Dec 12, 2024
CVE-2021-39207
8.4

CVE-2021-39207 is a YAML deserialization vulnerability in the ParlAI framework that allows arbitrary code execution when processing malicious YAML fil...

Sep 10, 2021
CVE-2020-17144
8.4

CVE-2020-17144 is a remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on ...

Dec 10, 2020
CVE-2022-41137
8.3

This vulnerability in Apache Hive Metastore allows authenticated users to achieve remote code execution by exploiting unsafe deserialization in partit...

Dec 5, 2024
CVE-2023-28782
8.3

CVE-2023-28782 is an unauthenticated PHP object injection vulnerability in Gravity Forms WordPress plugin that allows attackers to execute arbitrary c...

Dec 20, 2023
CVE-2023-34027
8.3

This CVE describes a PHP object injection vulnerability in the WordPress Recently Viewed Products plugin. Attackers can exploit deserialization of unt...

Dec 19, 2023
CVE-2023-37390
8.3

This CVE describes an unauthenticated PHP object injection vulnerability in the Themesflat Addons For Elementor WordPress plugin. Attackers can exploi...

Dec 19, 2023
CVE-2025-46183
8.2

CVE-2025-46183 is a deserialization vulnerability in pgCodeKeeper's Utils.deserialize function that allows remote code execution when processing malic...

Oct 24, 2025
CVE-2024-2721
8.2

This vulnerability allows attackers to execute arbitrary code on WordPress sites running the Social Media Share Buttons plugin by exploiting PHP objec...

Mar 20, 2024
CVE-2024-24796
8.2

This vulnerability allows remote attackers to execute arbitrary code via PHP object injection due to unsafe deserialization in the WpEvently WordPress...

Feb 12, 2024
CVE-2026-27206
8.1

Zumba Json Serializer versions 3.2.2 and below allow PHP Object Injection through untrusted JSON deserialization. The library's @type field can instan...

Feb 21, 2026
CVE-2026-27475
8.1

SPIP versions before 4.4.9 contain an insecure deserialization vulnerability in the public area through the table_valeur filter and DATA iterator. Att...

Feb 19, 2026
CVE-2026-0762
8.1

This vulnerability allows remote attackers to execute arbitrary code with root privileges on GPT Academic installations by exploiting insecure deseria...

Jan 23, 2026
CVE-2026-24009
8.1

This vulnerability allows remote code execution through malicious YAML input in docling-core library versions 2.21.0 to 2.48.3. Attackers can execute ...

Jan 22, 2026
CVE-2026-0726
8.1

The Nexter Extension plugin for WordPress has a PHP object injection vulnerability that allows unauthenticated attackers to inject malicious PHP objec...

Jan 20, 2026
CVE-2025-14044
8.1

The Visitor Logic Lite WordPress plugin up to version 1.0.3 contains a PHP object injection vulnerability that allows unauthenticated attackers to inj...

Dec 12, 2025
CVE-2025-58592
8.1

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the TranslatePress WordPress plugin. Succ...

Nov 6, 2025
CVE-2025-59007
8.1

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the TF Woo Product Grid Addon For Element...

Oct 22, 2025

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,013 CVEs classified as CWE-502, with 494 rated critical and 463 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free