CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (1,015)
This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the TF Woo Product Grid Addon For Element...
Oct 22, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Employee Spotlight WordPress plugin. ...
Aug 28, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP Easy Contact WordPress plugin. Suc...
Aug 28, 2025A deserialization vulnerability in Dell ControlVault3 and ControlVault3 Plus firmware allows arbitrary code execution when processing malicious respon...
Jun 13, 2025The Jupiter X Core WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'file' parameter. This vulnera...
Apr 26, 2025CVE-2025-3935 is a ViewState code injection vulnerability affecting ScreenConnect versions 25.2.3 and earlier. Attackers with compromised machine keys...
Apr 25, 2025This vulnerability allows unauthenticated attackers to inject PHP objects via deserialization of untrusted input in the ZoomSounds WordPress plugin. I...
Mar 5, 2025This CVE describes a PHP object injection vulnerability in the Puzzles WordPress theme that allows unauthenticated attackers to inject malicious PHP o...
Feb 13, 2025This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Locatoraid Store Locator WordPress pl...
Jan 7, 2025The Compare Products for WooCommerce WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted cookie data. Unauthen...
Jan 7, 2025The Print Science Designer WordPress plugin has a PHP object injection vulnerability that allows unauthenticated attackers to inject malicious PHP obj...
Dec 12, 2024An unauthenticated Java deserialization vulnerability in HPE Remote Insight Support allows remote attackers to execute arbitrary code on affected syst...
Nov 26, 2024CVE-2023-23649 is an unauthenticated PHP object injection vulnerability in the MainWP Links Manager Extension for WordPress. Attackers can exploit thi...
Mar 28, 2024The Essential Blocks WordPress plugin up to version 4.2.0 contains a PHP object injection vulnerability in the get_posts function. Unauthenticated att...
Oct 20, 2023CVE-2022-1415 is a deserialization vulnerability in Drools core utility classes that allows authenticated attackers to execute arbitrary code on affec...
Sep 11, 2023CVE-2022-40609 is an unsafe deserialization vulnerability in IBM SDK Java Technology Edition that allows remote attackers to execute arbitrary code on...
Aug 2, 2023CVE-2021-42631 is a deserialization vulnerability in PrinterLogic Web Stack that allows unauthenticated attackers to execute arbitrary code remotely. ...
Jan 31, 2022Apache Karaf's JMX implementation is vulnerable to Java deserialization attacks, allowing remote code execution on affected systems. This affects Apac...
Jan 26, 2022CVE-2021-23758 is a deserialization vulnerability in AjaxPro.2 that allows attackers to execute arbitrary .NET code by sending malicious serialized ob...
Dec 3, 2021This vulnerability in SuperMartijn642's Config Lib allows attackers to send malicious packets that exploit Java's ObjectInputStream deserialization, p...
Aug 5, 2021This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by deserializing untrusted data. It affects organi...
Jul 14, 2021This CVE describes a deserialization vulnerability in Huawei AnyOffice that allows remote code execution. Attackers can send crafted requests to explo...
Jun 29, 2021CVE-2020-7385 is a deserialization vulnerability in Metasploit Framework's drb_remote_codeexec module that allows remote code execution on the attacke...
Apr 23, 2021CVE-2021-26912 is a critical remote code execution vulnerability in NetMotion Mobility servers that allows unauthenticated attackers to execute arbitr...
Feb 8, 2021CVE-2021-26914 is a critical Java deserialization vulnerability in NetMotion Mobility Server's MvcUtil component that allows unauthenticated remote at...
Feb 8, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...
Jan 7, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. It affects applications using...
Jan 7, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...
Jan 6, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. It affects applications using...
Jan 6, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...
Jan 6, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...
Jan 6, 2021This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...
Dec 27, 2020This vulnerability in FasterXML jackson-databind allows remote code execution through deserialization of untrusted data. Attackers can exploit the int...
Dec 17, 2020This vulnerability allows an authenticated attacker to execute arbitrary code on Microsoft SharePoint servers by sending specially crafted deserialize...
Nov 11, 2025This vulnerability in Samsung DMS allows attackers to execute arbitrary code by exploiting insecure deserialization of untrusted data. Attackers can w...
Jul 29, 2025This vulnerability allows remote code execution in multi-node vLLM deployments using the V0 engine. Attackers can exploit unsafe pickle deserializatio...
May 6, 2025This vulnerability allows attackers to execute arbitrary code on WordPress sites using the Timber plugin by exploiting insecure deserialization of unt...
May 14, 2024This CVE describes a PHP object injection vulnerability in the GiveWP WordPress plugin. Attackers can exploit insecure deserialization to execute arbi...
Mar 28, 2024SolarWinds Access Rights Manager (ARM) contains a deserialization vulnerability that allows authenticated users to execute arbitrary code remotely. Th...
Feb 15, 2024This vulnerability in Allegro AI's ClearML client SDK allows remote code execution through deserialization of untrusted data. An attacker can upload a...
Feb 6, 2024CVE-2023-36439 is a remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on ...
Nov 14, 2023This vulnerability allows authenticated users of SolarWinds Access Rights Manager to execute arbitrary code remotely by abusing SolarWinds services. I...
Oct 19, 2023CVE-2023-35180 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows authenticated users to execute arbitrary code ...
Oct 19, 2023CVE-2023-36757 is a deserialization vulnerability in Microsoft Exchange Server that allows attackers to spoof email addresses and potentially execute ...
Sep 12, 2023CVE-2023-36745 is a remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on ...
Sep 12, 2023This vulnerability in Hitachi Vantara Pentaho Business Analytics Server allows remote code execution through insecure JSON deserialization. Attackers ...
May 24, 2023This vulnerability allows authenticated attackers with permission to create or configure objects in Jenkins to inject malicious content into Old Data ...
Jan 13, 2021CVE-2025-33252 is a deserialization vulnerability in NVIDIA's NeMo Framework that allows remote attackers to execute arbitrary code. This affects orga...
Feb 18, 2026A deserialization vulnerability in the OPC.Testclient utility within Rexroth IndraWorks allows attackers to execute arbitrary code by tricking users i...
Feb 18, 2026This vulnerability in Rexroth IndraWorks allows attackers to execute arbitrary code on a user's system by tricking them into opening a malicious file,...
Feb 18, 2026About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 1,015 CVEs classified as CWE-502, with 495 rated critical and 464 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free