CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,045
Total CVEs
516
Critical
473
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 62
2 Microsoft 36
3 Debian 22
4 Oracle 21
5 Ibm 20
6 Solarwinds 19
7 Netapp 16
8 Adobe 14
9 Fasterxml 12
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,045)

CVE-2020-24164
7.8

CVE-2020-24164 is a Java deserialization vulnerability in Taoensso Nippy library versions before 2.14.2. Attackers can craft malicious payloads that e...

Sep 11, 2020
CVE-2024-4200
7.7

This vulnerability allows a local threat actor to execute arbitrary code on systems running vulnerable versions of Progress Telerik Reporting. The att...

May 15, 2024
CVE-2021-23592
7.7

This vulnerability allows remote attackers to execute arbitrary code through insecure deserialization in the topthink/framework PHP package. It affect...

May 6, 2022
CVE-2022-25647
7.7

CVE-2022-25647 is a deserialization vulnerability in Google's Gson library versions before 2.8.9. Attackers can exploit the writeReplace() method in i...

May 1, 2022
CVE-2022-21647
7.7

CVE-2022-21647 is a deserialization vulnerability in CodeIgniter4's old() function that allows remote attackers to inject arbitrary objects and potent...

Jan 4, 2022
CVE-2025-23249
7.6

The NVIDIA NeMo Framework vulnerability allows remote attackers to execute arbitrary code by exploiting insecure deserialization of untrusted data. Th...

Apr 22, 2025
CVE-2024-52306
7.6

CVE-2024-52306 is a remote code execution vulnerability in FileManager's Backpack admin interface where untrusted data deserialization allows attacker...

Nov 13, 2024
CVE-2026-2020
7.5

The JS Archive List WordPress plugin is vulnerable to PHP object injection through the 'included' shortcode attribute. Authenticated attackers with Co...

Mar 7, 2026
CVE-2026-24892
7.5

openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization vulnerability in changelog processing. While no current explo...

Feb 20, 2026
CVE-2026-24891
7.5

CVE-2026-24891 is an unsafe deserialization vulnerability in openITCOCKPIT monitoring tool that allows PHP Object Injection when untrusted systems can...

Feb 20, 2026
CVE-2026-21511
7.5

This vulnerability allows attackers to spoof identities or data in Microsoft Office Outlook by exploiting insecure deserialization of untrusted data. ...

Feb 10, 2026
CVE-2026-25614
7.5

CVE-2026-25614 is a PHP object injection vulnerability in Blesta billing software that allows attackers to execute arbitrary code by deserializing unt...

Feb 3, 2026
CVE-2026-0772
7.5

This vulnerability allows authenticated remote attackers to execute arbitrary code on Langflow installations by exploiting insecure deserialization in...

Jan 23, 2026
CVE-2026-23737
7.5

CVE-2026-23737 is a deserialization vulnerability in seroval library versions 1.4.0 and below that allows arbitrary JavaScript code execution. Attacke...

Jan 21, 2026
CVE-2026-21226
7.5

This vulnerability in Azure Core shared client library for Python allows deserialization of untrusted data, enabling an authorized attacker to execute...

Jan 13, 2026
CVE-2025-14071
7.5

The Live Composer WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the dslc_module_posts_output shortc...

Dec 21, 2025
CVE-2025-63951
7.5

This CVE describes an insecure deserialization vulnerability in the MiczFlor RPi-Jukebox-RFID project's rss-mp3.php script. Remote unauthenticated att...

Dec 18, 2025
CVE-2025-63950
7.5

An insecure deserialization vulnerability in Twittodon's download.php script allows remote, unauthenticated attackers to inject arbitrary PHP objects ...

Dec 18, 2025
CVE-2025-60080
7.5

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in the PDF for Gravity...

Dec 18, 2025
CVE-2025-67779
7.5

This vulnerability allows attackers to send specially crafted HTTP requests to React Server Components Server Function endpoints, causing unsafe deser...

Dec 12, 2025
CVE-2025-55184
EPSS 19.2% 7.5

A pre-authentication denial of service vulnerability in React Server Components allows attackers to send specially crafted HTTP requests to Server Fun...

Dec 11, 2025
CVE-2025-62419
7.5

This CVE describes a JDBC URL injection vulnerability in DataEase data visualization platform. Attackers can inject malicious JDBC strings through the...

Oct 17, 2025
CVE-2025-8289
7.5

This vulnerability in the Redirection for Contact Form 7 WordPress plugin allows unauthenticated attackers to perform PHP object injection when specif...

Aug 20, 2025
CVE-2025-6464
7.5

The Forminator WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted input when form submissions are deleted. This a...

Jul 2, 2025
CVE-2025-3857
7.5

CVE-2025-3857 is a denial-of-service vulnerability in Amazon.IonDotnet's RawBinaryReader class that occurs when processing malformed or truncated bina...

Apr 21, 2025
CVE-2025-31103
7.5

CVE-2025-31103 is an untrusted data deserialization vulnerability in a-blog cms that allows attackers to upload arbitrary files to the server by sendi...

Mar 31, 2025
CVE-2025-2485
7.5

This vulnerability in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin allows PHP object injection via deserialization of un...

Mar 28, 2025
CVE-2024-10942
7.5

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP object injection via unsafe deserialization in the 'replace_serialize...

Mar 13, 2025
CVE-2025-24357
7.5

This vulnerability in vLLM allows remote code execution when loading malicious model checkpoints from Hugging Face. Attackers can execute arbitrary co...

Jan 27, 2025
CVE-2024-57762
7.5

MSFM before version 2025.01.01 contains a deserialization vulnerability in its pom.xml configuration file that could allow remote code execution. This...

Jan 15, 2025
CVE-2024-12627
7.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform PHP object injection via AJAX requests. Att...

Jan 11, 2025
CVE-2024-20150
7.5

This vulnerability in MediaTek modem firmware allows remote attackers to cause a system crash (denial of service) without authentication or user inter...

Jan 6, 2025
CVE-2024-56068
7.5

CVE-2024-56068 is a PHP object injection vulnerability in the WP SuperBackup WordPress plugin that allows attackers to execute arbitrary code through ...

Dec 31, 2024
CVE-2024-11839
7.5

This CVE describes a deserialization vulnerability in PlexTrac's Runbooks modules that allows attackers to inject malicious objects and write arbitrar...

Dec 13, 2024
CVE-2024-6960
7.5

CVE-2024-6960 is a Java deserialization vulnerability in the H2O machine learning platform that allows remote code execution when malicious models are...

Jul 21, 2024
CVE-2024-4157
7.5

This vulnerability allows authenticated WordPress users with contributor-level access or higher to perform PHP object injection via deserialization of...

May 22, 2024
CVE-2023-7064
7.5

This vulnerability in the Phlox theme's Shortcodes plugin allows authenticated WordPress users with subscriber-level access to perform PHP object inje...

May 2, 2024
CVE-2024-1895
7.5

The Event Monster WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input from custom meta values via shortc...

Apr 30, 2024
CVE-2024-22871
7.5

A vulnerability in Clojure versions 1.20 through 1.12.0-alpha5 allows attackers to cause denial of service (DoS) by exploiting the clojure.core$partia...

Feb 29, 2024
CVE-2023-1405
7.5

This vulnerability in the Formidable Forms WordPress plugin allows anonymous attackers to perform PHP Object Injection by exploiting insecure deserial...

Jan 16, 2024
CVE-2023-32513
7.5

CVE-2023-32513 is a PHP object injection vulnerability in the GiveWP WordPress plugin that allows attackers to execute arbitrary code through deserial...

Dec 28, 2023
CVE-2023-49819
7.5

This vulnerability allows attackers to execute arbitrary PHP code through deserialization of untrusted data in the WordPress Structured Content (JSON-...

Dec 19, 2023
CVE-2023-45672
7.5

Frigate network video recorder versions before 0.13.0 Beta 3 contain an unsafe YAML deserialization vulnerability in configuration endpoints. This all...

Oct 30, 2023
CVE-2023-46227
7.5

This vulnerability allows attackers to bypass security controls in Apache InLong by using tab characters to exploit a deserialization flaw. It affects...

Oct 19, 2023
CVE-2023-39410
7.5

This vulnerability in Apache Avro Java SDK allows attackers to cause out-of-memory conditions by sending specially crafted data during deserialization...

Sep 29, 2023
CVE-2023-24971
7.5

This vulnerability in IBM B2B Advanced Communications and IBM Multi-Enterprise Integration Gateway allows attackers to cause denial of service by dese...

Jul 31, 2023
CVE-2023-34434
7.5

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls and read arbitrary files. It aff...

Jul 25, 2023
CVE-2023-26548
7.5

The pgmng module in Huawei HarmonyOS and related products contains a deserialization vulnerability (CWE-502) that could allow attackers to execute arb...

Mar 27, 2023
CVE-2023-25558
7.5

DataHub's SSO authentication improperly processes id_token claims with {#sb64} prefixes, allowing unsafe Java deserialization via pac4j library. This ...

Feb 11, 2023
CVE-2022-0138
7.5

This vulnerability allows remote code execution through insecure deserialization in Cambium Networks wireless devices. Attackers can send specially cr...

Feb 18, 2022

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,045 CVEs classified as CWE-502, with 516 rated critical and 473 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free