CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,015
Total CVEs
495
Critical
464
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 60
2 Microsoft 36
3 Solarwinds 19
4 Ibm 18
5 Debian 18
6 Oracle 16
7 Adobe 14
8 Netapp 12
9 Ivanti 9
10 Givewp 9

All Deserialization of Untrusted Data CVEs (1,015)

CVE-2025-59007
8.1

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the TF Woo Product Grid Addon For Element...

Oct 22, 2025
CVE-2025-53583
8.1

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Employee Spotlight WordPress plugin. ...

Aug 28, 2025
CVE-2025-53572
8.1

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP Easy Contact WordPress plugin. Suc...

Aug 28, 2025
CVE-2025-24919
8.1

A deserialization vulnerability in Dell ControlVault3 and ControlVault3 Plus firmware allows arbitrary code execution when processing malicious respon...

Jun 13, 2025
CVE-2025-2105
8.1

The Jupiter X Core WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'file' parameter. This vulnera...

Apr 26, 2025
CVE-2025-3935
KEV EPSS 12.3% 8.1

CVE-2025-3935 is a ViewState code injection vulnerability affecting ScreenConnect versions 25.2.3 and earlier. Attackers with compromised machine keys...

Apr 25, 2025
CVE-2024-13777
8.1

This vulnerability allows unauthenticated attackers to inject PHP objects via deserialization of untrusted input in the ZoomSounds WordPress plugin. I...

Mar 5, 2025
CVE-2024-13770
8.1

This CVE describes a PHP object injection vulnerability in the Puzzles WordPress theme that allows unauthenticated attackers to inject malicious PHP o...

Feb 13, 2025
CVE-2024-56283
8.1

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Locatoraid Store Locator WordPress pl...

Jan 7, 2025
CVE-2024-12313
8.1

The Compare Products for WooCommerce WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted cookie data. Unauthen...

Jan 7, 2025
CVE-2024-12312
8.1

The Print Science Designer WordPress plugin has a PHP object injection vulnerability that allows unauthenticated attackers to inject malicious PHP obj...

Dec 12, 2024
CVE-2024-53673
8.1

An unauthenticated Java deserialization vulnerability in HPE Remote Insight Support allows remote attackers to execute arbitrary code on affected syst...

Nov 26, 2024
CVE-2023-23649
8.1

CVE-2023-23649 is an unauthenticated PHP object injection vulnerability in the MainWP Links Manager Extension for WordPress. Attackers can exploit thi...

Mar 28, 2024
CVE-2023-4386
8.1

The Essential Blocks WordPress plugin up to version 4.2.0 contains a PHP object injection vulnerability in the get_posts function. Unauthenticated att...

Oct 20, 2023
CVE-2022-1415
8.1

CVE-2022-1415 is a deserialization vulnerability in Drools core utility classes that allows authenticated attackers to execute arbitrary code on affec...

Sep 11, 2023
CVE-2022-40609
8.1

CVE-2022-40609 is an unsafe deserialization vulnerability in IBM SDK Java Technology Edition that allows remote attackers to execute arbitrary code on...

Aug 2, 2023
CVE-2021-42631
8.1

CVE-2021-42631 is a deserialization vulnerability in PrinterLogic Web Stack that allows unauthenticated attackers to execute arbitrary code remotely. ...

Jan 31, 2022
CVE-2021-41766
8.1

Apache Karaf's JMX implementation is vulnerable to Java deserialization attacks, allowing remote code execution on affected systems. This affects Apac...

Jan 26, 2022
CVE-2021-23758
8.1

CVE-2021-23758 is a deserialization vulnerability in AjaxPro.2 that allows attackers to execute arbitrary .NET code by sending malicious serialized ob...

Dec 3, 2021
CVE-2021-37632
8.1

This vulnerability in SuperMartijn642's Config Lib allows attackers to send malicious packets that exploit Java's ObjectInputStream deserialization, p...

Aug 5, 2021
CVE-2021-34520
8.1

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by deserializing untrusted data. It affects organi...

Jul 14, 2021
CVE-2021-22439
8.1

This CVE describes a deserialization vulnerability in Huawei AnyOffice that allows remote code execution. Attackers can send crafted requests to explo...

Jun 29, 2021
CVE-2020-7385
8.1

CVE-2020-7385 is a deserialization vulnerability in Metasploit Framework's drb_remote_codeexec module that allows remote code execution on the attacke...

Apr 23, 2021
CVE-2021-26912
8.1

CVE-2021-26912 is a critical remote code execution vulnerability in NetMotion Mobility servers that allows unauthenticated attackers to execute arbitr...

Feb 8, 2021
CVE-2021-26914
8.1

CVE-2021-26914 is a critical Java deserialization vulnerability in NetMotion Mobility Server's MvcUtil component that allows unauthenticated remote at...

Feb 8, 2021
CVE-2020-36183
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...

Jan 7, 2021
CVE-2020-36180
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. It affects applications using...

Jan 7, 2021
CVE-2020-36185
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...

Jan 6, 2021
CVE-2020-36187
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. It affects applications using...

Jan 6, 2021
CVE-2020-36189
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...

Jan 6, 2021
CVE-2020-36181
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...

Jan 6, 2021
CVE-2020-35728
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...

Dec 27, 2020
CVE-2020-35491
8.1

This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...

Dec 17, 2020
CVE-2025-62204
8.0

This vulnerability allows an authenticated attacker to execute arbitrary code on Microsoft SharePoint servers by sending specially crafted deserialize...

Nov 11, 2025
CVE-2025-53078
8.0

This vulnerability in Samsung DMS allows attackers to execute arbitrary code by exploiting insecure deserialization of untrusted data. Attackers can w...

Jul 29, 2025
CVE-2025-30165
8.0

This vulnerability allows remote code execution in multi-node vLLM deployments using the V0 engine. Attackers can exploit unsafe pickle deserializatio...

May 6, 2025
CVE-2024-29800
8.0

This vulnerability allows attackers to execute arbitrary code on WordPress sites using the Timber plugin by exploiting insecure deserialization of unt...

May 14, 2024
CVE-2024-30229
8.0

This CVE describes a PHP object injection vulnerability in the GiveWP WordPress plugin. Attackers can exploit insecure deserialization to execute arbi...

Mar 28, 2024
CVE-2024-23478
8.0

SolarWinds Access Rights Manager (ARM) contains a deserialization vulnerability that allows authenticated users to execute arbitrary code remotely. Th...

Feb 15, 2024
CVE-2024-24590
8.0

This vulnerability in Allegro AI's ClearML client SDK allows remote code execution through deserialization of untrusted data. An attacker can upload a...

Feb 6, 2024
CVE-2023-36439
8.0

CVE-2023-36439 is a remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on ...

Nov 14, 2023
CVE-2023-35186
8.0

This vulnerability allows authenticated users of SolarWinds Access Rights Manager to execute arbitrary code remotely by abusing SolarWinds services. I...

Oct 19, 2023
CVE-2023-35180
8.0

CVE-2023-35180 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows authenticated users to execute arbitrary code ...

Oct 19, 2023
CVE-2023-36757
8.0

CVE-2023-36757 is a deserialization vulnerability in Microsoft Exchange Server that allows attackers to spoof email addresses and potentially execute ...

Sep 12, 2023
CVE-2023-36745
8.0

CVE-2023-36745 is a remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on ...

Sep 12, 2023
CVE-2022-4815
8.0

This vulnerability in Hitachi Vantara Pentaho Business Analytics Server allows remote code execution through insecure JSON deserialization. Attackers ...

May 24, 2023
CVE-2021-21604
8.0

This vulnerability allows authenticated attackers with permission to create or configure objects in Jenkins to inject malicious content into Old Data ...

Jan 13, 2021
CVE-2025-33252
7.8

CVE-2025-33252 is a deserialization vulnerability in NVIDIA's NeMo Framework that allows remote attackers to execute arbitrary code. This affects orga...

Feb 18, 2026
CVE-2025-60035
7.8

A deserialization vulnerability in the OPC.Testclient utility within Rexroth IndraWorks allows attackers to execute arbitrary code by tricking users i...

Feb 18, 2026
CVE-2025-60037
7.8

This vulnerability in Rexroth IndraWorks allows attackers to execute arbitrary code on a user's system by tricking them into opening a malicious file,...

Feb 18, 2026

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,015 CVEs classified as CWE-502, with 495 rated critical and 464 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free