CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (1,044)
SolarWinds Observability Self-Hosted has a deserialization vulnerability that allows authenticated low-privilege users to escalate privileges locally....
Jul 24, 2025This vulnerability allows a local attacker to escalate privileges by exploiting a flaw in the communication protocol between server processes and serv...
Jul 11, 2025This vulnerability in Delta Electronics DTN Soft allows remote code execution through deserialization of untrusted data in project files. Attackers ca...
Jun 30, 2025This vulnerability allows remote code execution through deserialization of untrusted data in Delta Electronics DTM Soft project files. Attackers can c...
Jun 30, 2025This vulnerability allows an unauthorized attacker to execute arbitrary code on SharePoint servers by exploiting insecure deserialization of untrusted...
May 13, 2025GFI MailEssentials versions before 21.8 contain a local privilege escalation vulnerability where an attacker with local access can send a crafted seri...
Apr 28, 2025This vulnerability allows arbitrary code execution through deserialization of untrusted data in NI G Web Development Software. Attackers can exploit i...
Mar 6, 2025This CVE describes a deserialization vulnerability in Schneider Electric software where a non-admin authenticated user can execute arbitrary code by o...
Jan 17, 2025This vulnerability allows attackers to bypass security features in Microsoft Excel, potentially enabling malicious code execution by opening specially...
Jan 14, 2025This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager (EPM) systems through deserialization ...
Jan 14, 2025This vulnerability in multiple Siemens industrial automation products allows attackers to execute arbitrary code by exploiting improper input sanitiza...
Dec 10, 2024This vulnerability allows local privilege escalation on Android devices through unsafe deserialization in the Settings app. Attackers can exploit this...
Nov 13, 2024This vulnerability allows remote code execution through insecure deserialization in Progress Telerik UI for WPF. Attackers can exploit this to execute...
Nov 13, 2024A deserialization vulnerability in NI VeriStand allows remote code execution when a user opens a malicious project file. This affects VeriStand 2024 Q...
Jul 22, 2024This vulnerability allows local privilege escalation on Android devices through unsafe deserialization in ZygoteProcess.java. An attacker with WRITE_S...
Jul 9, 2024This vulnerability allows attackers to execute arbitrary code on affected Siemens industrial control systems by exploiting insecure .NET BinaryFormatt...
Jul 9, 2024Dell Common Event Enabler versions 8.9.10.0 and earlier contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attack...
Jun 12, 2024CVE-2024-37064 is a deserialization vulnerability in ydata-profiling library versions 3.7.0+. Attackers can craft malicious datasets that execute arbi...
Jun 4, 2024This vulnerability in ydata-profiling library allows remote code execution when a maliciously crafted report is loaded. Attackers can execute arbitrar...
Jun 4, 2024This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malic...
May 14, 2024This vulnerability allows remote code execution through deserialization of untrusted data in NI FlexLogger and InstrumentStudio. Attackers can exploit...
May 14, 2024CVE-2024-34072 is a deserialization vulnerability in the sagemaker-python-sdk's NumpyDeserializer module that allows remote code execution when proces...
May 3, 2024This CVE describes a deserialization vulnerability in Schneider Electric software that allows remote code execution when a malicious project file is l...
Mar 18, 2024This vulnerability allows an attacker with a low-privilege user account to escalate privileges by sending a malicious serialized object. It affects Sc...
Jan 9, 2024This vulnerability allows a local malicious user to exploit insecure deserialization in Dell Alienware Command Center to execute arbitrary code on the...
Sep 4, 2023CVE-2023-24621 is a deserialization vulnerability in Esoteric YamlBeans that allows attackers to execute arbitrary Java code by crafting malicious YAM...
Aug 25, 2023CVE-2021-31680 is a deserialization vulnerability in YOLOv5 that allows attackers to execute arbitrary code by providing a malicious YAML configuratio...
Jul 31, 2023This vulnerability allows authenticated attackers to execute arbitrary code with SYSTEM privileges on Windows Server Update Service (WSUS) servers. It...
Jul 11, 2023This vulnerability allows local privilege escalation on Android devices through unsafe deserialization in the 'run of multiple files' component. Attac...
Jun 15, 2023This CVE describes a deserialization vulnerability in the Dashboard module that allows remote code execution when a user opens a malicious file. Attac...
Jun 14, 2023CVE-2022-28685 is a remote code execution vulnerability in AVEVA Edge 2020 SP2 Patch 0 (version 4201.2111.1802.0000) that allows attackers to execute ...
Mar 29, 2023CVE-2023-1399 is a deserialization vulnerability in N6854A Geolocation Server that allows attackers to execute arbitrary code by sending malicious dat...
Mar 27, 2023This CVE describes a deserialization vulnerability in Mitsubishi Electric's GENESIS64, ICONICS Suite, and MC Works64 products. An unauthenticated atta...
Jul 20, 2022This CVE describes a deserialization vulnerability in Mitsubishi Electric's GENESIS64, ICONICS Suite, and MC Works64 software. An unauthenticated atta...
Jul 20, 2022CVE-2022-27579 is a deserialization vulnerability in Flexi Soft Designer that allows attackers to execute arbitrary code by tricking users into openin...
Jul 19, 2022This vulnerability in Android's GPS navigation message handling allows local privilege escalation without user interaction. It affects Android devices...
Dec 15, 2021CVE-2021-41078 is a deserialization vulnerability in Nameko that allows remote code execution when processing malicious configuration files. Attackers...
Oct 26, 2021This vulnerability allows local privilege escalation on Android 11 devices through unsafe deserialization in the ParsedIntentInfo component. Attackers...
Oct 6, 2021CVE-2021-32568 is a deserialization vulnerability in mrdoc documentation software that allows attackers to execute arbitrary code by sending malicious...
Sep 6, 2021This CVE describes an unsafe deserialization vulnerability in CODESYS Development System that allows arbitrary command execution when processing malic...
Aug 25, 2021This CVE describes an unsafe deserialization vulnerability in CODESYS Development System that allows arbitrary command execution when processing malic...
Aug 18, 2021This CVE describes an unsafe deserialization vulnerability in CODESYS Development System's Profile.FromFile() function. Attackers can craft malicious ...
Aug 5, 2021This CVE-2021-21865 is an unsafe deserialization vulnerability in CODESYS Development System that allows arbitrary command execution when processing m...
Aug 2, 2021This vulnerability allows local attackers with low-privileged access to escalate privileges to SYSTEM level via insecure deserialization in SolarWinds...
Apr 22, 2021This vulnerability in JetBrains IntelliJ IDEA allows local code execution through insecure deserialization of workspace models. Attackers could exploi...
Feb 3, 2021CVE-2020-28948 is a deserialization vulnerability in Archive_Tar that allows attackers to execute arbitrary code via PHAR archive exploitation. The vu...
Nov 19, 2020This vulnerability allows arbitrary code execution when fabric8-maven-plugin processes malicious YAML configuration files during builds. It affects de...
Oct 22, 2020This vulnerability allows remote code execution on Schneider Electric SCADAPack 7x Remote Connect software through malicious project files. Attackers ...
Sep 16, 2020This vulnerability allows remote code execution on SCADAPack x70 Security Administrator systems through malicious .SDB files. Attackers can execute ar...
Sep 16, 2020CVE-2020-24164 is a Java deserialization vulnerability in Taoensso Nippy library versions before 2.14.2. Attackers can craft malicious payloads that e...
Sep 11, 2020About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 1,044 CVEs classified as CWE-502, with 515 rated critical and 473 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free