CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

1,055
Total CVEs
519
Critical
480
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 63
2 Microsoft 37
3 Debian 24
4 Oracle 22
5 Ibm 22
6 Solarwinds 19
7 Netapp 17
8 Adobe 14
9 Fasterxml 13
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (1,055)

CVE-2025-59713
6.8

CVE-2025-59713 is an unsafe deserialization vulnerability in Snipe-IT versions before 8.1.18 that could allow remote code execution. This affects all ...

Sep 19, 2025
CVE-2024-39673
6.8

This vulnerability involves a serialization/deserialization mismatch in Huawei's iAware module that could allow attackers to access sensitive informat...

Jul 25, 2024
CVE-2025-24794
6.7

The Snowflake Connector for Python uses pickle for OCSP response cache serialization, allowing local attackers to execute arbitrary code via cache poi...

Jan 29, 2025
CVE-2026-27794
6.6

LangGraph Checkpoint versions before 4.0.0 contain a remote code execution vulnerability in the caching layer when applications enable cache backends ...

Feb 25, 2026
CVE-2025-39565
6.6

A PHP object injection vulnerability in Melapress Login Security WordPress plugin allows attackers to execute arbitrary code through deserialization o...

Apr 16, 2025
CVE-2021-27017
6.6

CVE-2021-27017 is a deserialization vulnerability in Puppet Agent that allows attackers to execute arbitrary code by supplying malicious serialized da...

Feb 7, 2025
CVE-2024-13296
6.6

This vulnerability in Drupal Mailjet module allows attackers to inject malicious objects through deserialization of untrusted data, potentially leadin...

Jan 9, 2025
CVE-2021-4451
6.6

The NinjaFirewall WordPress plugin up to version 4.3.3 contains an authenticated PHAR deserialization vulnerability. This allows authenticated attacke...

Oct 16, 2024
CVE-2026-1235
6.5

The WP eCommerce WordPress plugin through version 3.15.1 has a PHP object injection vulnerability that allows unauthenticated attackers to execute arb...

Feb 11, 2026
CVE-2025-70559
6.5

pdfminer.six contains an insecure deserialization vulnerability where Python pickle is used to deserialize CMap cache files without validation. An att...

Feb 3, 2026
CVE-2025-67535
6.5

This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the WP Maps WordPress plugin. All Wor...

Dec 9, 2025
CVE-2025-66073
6.5

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WP Webhooks WordPress plugin. Attacke...

Nov 21, 2025
CVE-2025-63617
6.5

This vulnerability allows remote code execution through unsafe fastjson deserialization in ktg-mes systems. Attackers can exploit this by sending mali...

Nov 10, 2025
CVE-2025-60834
6.5

A deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code by sending specially crafted input to the applicatio...

Oct 8, 2025
CVE-2025-60828
6.5

WukongCRM 9.0-JAVA contains a fastjson deserialization vulnerability in the /OaExamine/setOaExamine interface that allows remote code execution. This ...

Oct 8, 2025
CVE-2025-60830
6.5

Redragon ERP v1.0 contains a Shiro deserialization vulnerability due to the use of default Shiro cryptographic keys. This allows attackers to execute ...

Oct 8, 2025
CVE-2025-59328
6.5

This CVE describes a denial-of-service vulnerability in Apache Fory caused by insecure deserialization of untrusted data. Remote attackers can send sp...

Sep 15, 2025
CVE-2025-27526
6.5

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls through JDBC URL encoding and ba...

May 28, 2025
CVE-2024-39334
6.5

MENDELSON AS4 client software before version 2024 B376 has a deserialization vulnerability where malicious XML data from a trading partner can trigger...

Jun 23, 2024
CVE-2024-3591
6.5

This vulnerability in the Geo Controller WordPress plugin allows unauthenticated attackers to perform PHP Object Injection by sending specially crafte...

May 1, 2024
CVE-2025-9191
6.3

The Houzez WordPress theme is vulnerable to PHP object injection through deserialization of untrusted input in saved-search-item.php. This allows auth...

Nov 26, 2025
CVE-2023-51642
6.3

This vulnerability allows remote authenticated attackers to execute arbitrary code on affected Allegra installations by exploiting a deserialization f...

Nov 22, 2024
CVE-2024-9917
6.3

This critical vulnerability in HuangDou UTCMS V9 allows remote attackers to execute arbitrary code through insecure deserialization in the template_cr...

Oct 13, 2024
CVE-2024-6944
6.3

This critical vulnerability in ZhongBangKeJi CRMEB allows remote attackers to execute arbitrary code through deserialization of untrusted data in the ...

Jul 21, 2024
CVE-2024-6943
6.3

This CVE describes a critical remote code execution vulnerability in ZhongBangKeJi CRMEB e-commerce platform. Attackers can exploit insecure deseriali...

Jul 21, 2024
CVE-2024-6645
6.3

This critical vulnerability in WuKongOpenSource Wukong_nocode allows remote attackers to execute arbitrary code through insecure deserialization in th...

Jul 10, 2024
CVE-2023-32737
6.3

This vulnerability in SIMATIC STEP 7 Safety V18 allows attackers to execute arbitrary code by exploiting insecure .NET BinaryFormatter deserialization...

Jul 9, 2024
CVE-2024-5352
6.3

This critical vulnerability in anji-plus AJ-Report allows remote attackers to execute arbitrary code through insecure deserialization in the validatio...

May 26, 2024
CVE-2024-4699
6.3

This critical vulnerability in D-Link DAR-8000-10 devices allows remote attackers to execute arbitrary code through deserialization attacks targeting ...

May 14, 2024
CVE-2025-2251
6.2

This vulnerability allows remote code execution on WildFly and JBoss EAP servers through untrusted deserialization in the EJB remote invocation mechan...

Apr 7, 2025
CVE-2024-34075
6.2

CVE-2024-34075 is a deserialization vulnerability in the kurwov Markov chain library where malicious strings containing '__proto__ ' (with trailing sp...

May 3, 2024
CVE-2023-38264
5.9

This vulnerability in IBM SDK Java Technology Edition's Object Request Broker allows attackers to cause denial of service by bypassing deserialization...

May 14, 2024
CVE-2025-55136
5.7

CVE-2025-55136 is an insecure deserialization vulnerability in ERC (Emotion Recognition in Conversation) software versions through 0.3. Attackers can ...

Aug 7, 2025
CVE-2025-8871
5.6

The Everest Forms Pro WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the mime_content_type() functio...

Nov 5, 2025
CVE-2025-2939
5.6

The Ninja Tables WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the args[callback] parameter. This a...

Jun 3, 2025
CVE-2025-13467
5.5

This vulnerability allows authenticated Keycloak realm administrators to trigger deserialization of untrusted Java objects by configuring a malicious ...

Nov 25, 2025
CVE-2025-54640
5.5

CVE-2025-54640 is a ParcelMismatch vulnerability in attribute deserialization that allows attackers to manipulate data structures during deserializati...

Aug 6, 2025
CVE-2025-54639
5.5

CVE-2025-54639 is a deserialization vulnerability in Huawei devices that allows attackers to manipulate attribute data during deserialization. Success...

Aug 6, 2025
CVE-2025-54638
5.5

This vulnerability involves inconsistent read/write serialization in the ad module, which could allow an attacker to disrupt the availability of the a...

Aug 6, 2025
CVE-2025-54620
5.5

This CVE describes a deserialization vulnerability in the ability module where untrusted data can be processed, potentially leading to denial of servi...

Aug 6, 2025
CVE-2025-20275
5.3

This vulnerability allows unauthenticated attackers to execute arbitrary code on Cisco Unified CCX Editor systems by exploiting insecure Java deserial...

Jun 4, 2025
CVE-2024-10749
5.0

This critical vulnerability in ThinkAdmin allows remote attackers to execute arbitrary code through insecure deserialization in the Plugs.php file. It...

Nov 4, 2024
CVE-2026-23685
4.4

This CVE describes a deserialization vulnerability in SAP NetWeaver's JMS service that allows authenticated administrators with local access to submit...

Feb 10, 2026
CVE-2024-34751
4.4

This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the WebToffee Order Export & Order Im...

May 16, 2024
CVE-2024-34433
4.4

This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the One Click Demo Import WordPress p...

May 14, 2024
CVE-2019-2391
4.2

A vulnerability in MongoDB's js-bson library versions 1.1.3 and earlier allows incorrect parsing of certain JSON inputs, leading to improper BSON seri...

Mar 31, 2020
CVE-2026-24656
3.7

Apache Karaf Decanter's log socket collector has a deserialization vulnerability on port 4560 without authentication. Attackers can bypass allowed cla...

Jan 26, 2026
CVE-2025-15579
N/A

CVE-2025-15579 is a deserialization vulnerability in OpenText Directory Services that allows attackers to inject malicious objects. If exploited, it c...

Feb 18, 2026
CVE-2026-26220
N/A

LightLLM versions 1.1.0 and earlier contain an unauthenticated remote code execution vulnerability in PD disaggregation mode. Attackers can send malic...

Feb 17, 2026
CVE-2026-26221
N/A

This vulnerability in Hyland OnBase allows unauthenticated attackers to send crafted .NET Remoting requests to the Workflow Timer Service on TCP port ...

Feb 13, 2026

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 1,055 CVEs classified as CWE-502, with 519 rated critical and 480 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free