CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,044
Total CVEs
515
Critical
473
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 62
2 Microsoft 36
3 Debian 22
4 Ibm 20
5 Oracle 20
6 Solarwinds 19
7 Netapp 16
8 Adobe 14
9 Fasterxml 12
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,044)

CVE-2025-26397
7.8

SolarWinds Observability Self-Hosted has a deserialization vulnerability that allows authenticated low-privilege users to escalate privileges locally....

Jul 24, 2025
CVE-2025-30025
7.8

This vulnerability allows a local attacker to escalate privileges by exploiting a flaw in the communication protocol between server processes and serv...

Jul 11, 2025
CVE-2025-53416
7.8

This vulnerability in Delta Electronics DTN Soft allows remote code execution through deserialization of untrusted data in project files. Attackers ca...

Jun 30, 2025
CVE-2025-53415
7.8

This vulnerability allows remote code execution through deserialization of untrusted data in Delta Electronics DTM Soft project files. Attackers can c...

Jun 30, 2025
CVE-2025-30382
7.8

This vulnerability allows an unauthorized attacker to execute arbitrary code on SharePoint servers by exploiting insecure deserialization of untrusted...

May 13, 2025
CVE-2025-34489
7.8

GFI MailEssentials versions before 21.8 contain a local privilege escalation vulnerability where an attacker with local access can send a crafted seri...

Apr 28, 2025
CVE-2024-12742
7.8

This vulnerability allows arbitrary code execution through deserialization of untrusted data in NI G Web Development Software. Attackers can exploit i...

Mar 6, 2025
CVE-2024-12703
7.8

This CVE describes a deserialization vulnerability in Schneider Electric software where a non-admin authenticated user can execute arbitrary code by o...

Jan 17, 2025
CVE-2025-21364
7.8

This vulnerability allows attackers to bypass security features in Microsoft Excel, potentially enabling malicious code execution by opening specially...

Jan 14, 2025
CVE-2024-13163
7.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager (EPM) systems through deserialization ...

Jan 14, 2025
CVE-2024-49849
7.8

This vulnerability in multiple Siemens industrial automation products allows attackers to execute arbitrary code by exploiting improper input sanitiza...

Dec 10, 2024
CVE-2024-43080
7.8

This vulnerability allows local privilege escalation on Android devices through unsafe deserialization in the Settings app. Attackers can exploit this...

Nov 13, 2024
CVE-2024-10012
7.8

This vulnerability allows remote code execution through insecure deserialization in Progress Telerik UI for WPF. Attackers can exploit this to execute...

Nov 13, 2024
CVE-2024-6675
7.8

A deserialization vulnerability in NI VeriStand allows remote code execution when a user opens a malicious project file. This affects VeriStand 2024 Q...

Jul 22, 2024
CVE-2024-31317
7.8

This vulnerability allows local privilege escalation on Android devices through unsafe deserialization in ZygoteProcess.java. An attacker with WRITE_S...

Jul 9, 2024
CVE-2022-45147
7.8

This vulnerability allows attackers to execute arbitrary code on affected Siemens industrial control systems by exploiting insecure .NET BinaryFormatt...

Jul 9, 2024
CVE-2024-28964
7.8

Dell Common Event Enabler versions 8.9.10.0 and earlier contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attack...

Jun 12, 2024
CVE-2024-37064
7.8

CVE-2024-37064 is a deserialization vulnerability in ydata-profiling library versions 3.7.0+. Attackers can craft malicious datasets that execute arbi...

Jun 4, 2024
CVE-2024-37062
7.8

This vulnerability in ydata-profiling library allows remote code execution when a maliciously crafted report is loaded. Attackers can execute arbitrar...

Jun 4, 2024
CVE-2024-30042
7.8

This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malic...

May 14, 2024
CVE-2024-4044
7.8

This vulnerability allows remote code execution through deserialization of untrusted data in NI FlexLogger and InstrumentStudio. Attackers can exploit...

May 14, 2024
CVE-2024-34072
7.8

CVE-2024-34072 is a deserialization vulnerability in the sagemaker-python-sdk's NumpyDeserializer module that allows remote code execution when proces...

May 3, 2024
CVE-2024-2229
7.8

This CVE describes a deserialization vulnerability in Schneider Electric software that allows remote code execution when a malicious project file is l...

Mar 18, 2024
CVE-2023-7032
7.8

This vulnerability allows an attacker with a low-privilege user account to escalate privileges by sending a malicious serialized object. It affects Sc...

Jan 9, 2024
CVE-2023-28072
7.8

This vulnerability allows a local malicious user to exploit insecure deserialization in Dell Alienware Command Center to execute arbitrary code on the...

Sep 4, 2023
CVE-2023-24621
7.8

CVE-2023-24621 is a deserialization vulnerability in Esoteric YamlBeans that allows attackers to execute arbitrary Java code by crafting malicious YAM...

Aug 25, 2023
CVE-2021-31680
7.8

CVE-2021-31680 is a deserialization vulnerability in YOLOv5 that allows attackers to execute arbitrary code by providing a malicious YAML configuratio...

Jul 31, 2023
CVE-2023-35317
7.8

This vulnerability allows authenticated attackers to execute arbitrary code with SYSTEM privileges on Windows Server Update Service (WSUS) servers. It...

Jul 11, 2023
CVE-2023-21124
7.8

This vulnerability allows local privilege escalation on Android devices through unsafe deserialization in the 'run of multiple files' component. Attac...

Jun 15, 2023
CVE-2023-3001
7.8

This CVE describes a deserialization vulnerability in the Dashboard module that allows remote code execution when a user opens a malicious file. Attac...

Jun 14, 2023
CVE-2022-28685
7.8

CVE-2022-28685 is a remote code execution vulnerability in AVEVA Edge 2020 SP2 Patch 0 (version 4201.2111.1802.0000) that allows attackers to execute ...

Mar 29, 2023
CVE-2023-1399
7.8

CVE-2023-1399 is a deserialization vulnerability in N6854A Geolocation Server that allows attackers to execute arbitrary code by sending malicious dat...

Mar 27, 2023
CVE-2022-33315
7.8

This CVE describes a deserialization vulnerability in Mitsubishi Electric's GENESIS64, ICONICS Suite, and MC Works64 products. An unauthenticated atta...

Jul 20, 2022
CVE-2022-33320
7.8

This CVE describes a deserialization vulnerability in Mitsubishi Electric's GENESIS64, ICONICS Suite, and MC Works64 software. An unauthenticated atta...

Jul 20, 2022
CVE-2022-27579
7.8

CVE-2022-27579 is a deserialization vulnerability in Flexi Soft Designer that allows attackers to execute arbitrary code by tricking users into openin...

Jul 19, 2022
CVE-2021-0970
7.8

This vulnerability in Android's GPS navigation message handling allows local privilege escalation without user interaction. It affects Android devices...

Dec 15, 2021
CVE-2021-41078
7.8

CVE-2021-41078 is a deserialization vulnerability in Nameko that allows remote code execution when processing malicious configuration files. Attackers...

Oct 26, 2021
CVE-2021-0685
7.8

This vulnerability allows local privilege escalation on Android 11 devices through unsafe deserialization in the ParsedIntentInfo component. Attackers...

Oct 6, 2021
CVE-2021-32568
7.8

CVE-2021-32568 is a deserialization vulnerability in mrdoc documentation software that allows attackers to execute arbitrary code by sending malicious...

Sep 6, 2021
CVE-2021-21869
7.8

This CVE describes an unsafe deserialization vulnerability in CODESYS Development System that allows arbitrary command execution when processing malic...

Aug 25, 2021
CVE-2021-21868
7.8

This CVE describes an unsafe deserialization vulnerability in CODESYS Development System that allows arbitrary command execution when processing malic...

Aug 18, 2021
CVE-2021-21863
7.8

This CVE describes an unsafe deserialization vulnerability in CODESYS Development System's Profile.FromFile() function. Attackers can craft malicious ...

Aug 5, 2021
CVE-2021-21865
7.8

This CVE-2021-21865 is an unsafe deserialization vulnerability in CODESYS Development System that allows arbitrary command execution when processing m...

Aug 2, 2021
CVE-2021-27277
7.8

This vulnerability allows local attackers with low-privileged access to escalate privileges to SYSTEM level via insecure deserialization in SolarWinds...

Apr 22, 2021
CVE-2021-25758
7.8

This vulnerability in JetBrains IntelliJ IDEA allows local code execution through insecure deserialization of workspace models. Attackers could exploi...

Feb 3, 2021
CVE-2020-28948
7.8

CVE-2020-28948 is a deserialization vulnerability in Archive_Tar that allows attackers to execute arbitrary code via PHAR archive exploitation. The vu...

Nov 19, 2020
CVE-2020-10721
7.8

This vulnerability allows arbitrary code execution when fabric8-maven-plugin processes malicious YAML configuration files during builds. It affects de...

Oct 22, 2020
CVE-2020-7528
7.8

This vulnerability allows remote code execution on Schneider Electric SCADAPack 7x Remote Connect software through malicious project files. Attackers ...

Sep 16, 2020
CVE-2020-7532
7.8

This vulnerability allows remote code execution on SCADAPack x70 Security Administrator systems through malicious .SDB files. Attackers can execute ar...

Sep 16, 2020
CVE-2020-24164
7.8

CVE-2020-24164 is a Java deserialization vulnerability in Taoensso Nippy library versions before 2.14.2. Attackers can craft malicious payloads that e...

Sep 11, 2020

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,044 CVEs classified as CWE-502, with 515 rated critical and 473 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free