CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

992
Total CVEs
479
Critical
457
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 56
2 Microsoft 35
3 Solarwinds 19
4 Ibm 16
5 Debian 14
6 Adobe 14
7 Oracle 12
8 Netapp 10
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (992)

CVE-2025-31927
9.8

CVE-2025-31927 is a PHP object injection vulnerability in the Acerola WordPress theme that allows attackers to execute arbitrary code through deserial...

May 23, 2025
CVE-2025-31423
9.8

CVE-2025-31423 is a PHP object injection vulnerability in the Umberto WordPress theme that allows attackers to execute arbitrary code by exploiting in...

May 23, 2025
CVE-2025-31631
9.8

This CVE describes a PHP object injection vulnerability in the Fish House WordPress theme due to insecure deserialization of untrusted data. Attackers...

May 23, 2025
CVE-2025-31069
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the HotStar WordPress theme. Successful e...

May 23, 2025
CVE-2025-31049
9.8

CVE-2025-31049 is a PHP object injection vulnerability in the Dash WordPress theme that allows attackers to execute arbitrary code through deserializa...

May 23, 2025
CVE-2025-47277
9.8

This vulnerability in vLLM versions 0.6.5 through 0.8.4 exposes the TCPStore interface on ALL network interfaces instead of only the specified private...

May 20, 2025
CVE-2025-39354
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Grand Conference WordPress theme. Suc...

May 19, 2025
CVE-2025-39356
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Foodbakery Sticky Cart WordPress plug...

May 19, 2025
CVE-2025-32928
9.8

This vulnerability in the ThemeGoods Altair WordPress theme allows attackers to inject malicious objects through deserialization of untrusted data. It...

May 19, 2025
CVE-2025-39349
9.8

CVE-2025-39349 is a PHP object injection vulnerability in the CiyaShop WordPress theme that allows attackers to execute arbitrary code through deseria...

May 19, 2025
CVE-2025-47581
9.8

This vulnerability allows attackers to execute arbitrary code on WordPress sites by exploiting insecure deserialization in the Events Calendar Registr...

May 19, 2025
CVE-2025-39410
9.8

This vulnerability allows remote attackers to execute arbitrary PHP code through deserialization of untrusted data in the Smart Sections Theme Builder...

May 19, 2025
CVE-2025-47784
9.8

Emlog versions 2.5.13 and prior contain a deserialization vulnerability where a user can craft a malicious nickname to cause deserialization failure. ...

May 15, 2025
CVE-2025-0855
9.8

The PGS Core WordPress plugin is vulnerable to PHP Object Injection via insecure deserialization in the 'import_header' function, allowing unauthentic...

May 6, 2025
CVE-2025-43851
9.8

This vulnerability allows remote code execution through unsafe deserialization in Retrieval-based-Voice-Conversion-WebUI. Attackers can exploit the mo...

May 5, 2025
CVE-2025-43849
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Retrieval-based-Voice-Conversion-WebUI by exploiting unsafe de...

May 5, 2025
CVE-2025-43846
9.8

CVE-2025-43846 is a critical unsafe deserialization vulnerability in Retrieval-based-Voice-Conversion-WebUI that allows remote code execution. Attacke...

May 5, 2025
CVE-2025-43848
9.8

CVE-2025-43848 is an unsafe deserialization vulnerability in Retrieval-based-Voice-Conversion-WebUI that allows remote code execution. Attackers can e...

May 5, 2025
CVE-2025-32434
9.8

A critical Remote Command Execution vulnerability exists in PyTorch when loading models with torch.load(weights_only=True). Attackers can craft malici...

Apr 18, 2025
CVE-2025-29953
9.8

This vulnerability allows malicious Apache ActiveMQ servers to send specially crafted responses to NMS OpenWire clients, leading to arbitrary code exe...

Apr 18, 2025
CVE-2025-39550
9.8

CVE-2025-39550 is a PHP object injection vulnerability in the Shahjahan Jewel FluentCommunity WordPress plugin that allows attackers to execute arbitr...

Apr 17, 2025
CVE-2025-32658
9.8

This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable HelpGent plugin by exploiting insecure deseria...

Apr 17, 2025
CVE-2025-32572
9.8

CVE-2025-32572 is a PHP object injection vulnerability in the Kata Plus WordPress plugin that allows attackers to execute arbitrary code through deser...

Apr 17, 2025
CVE-2025-27286
9.8

This vulnerability allows remote attackers to execute arbitrary code through PHP object injection via deserialization of untrusted data in the Saoshya...

Apr 17, 2025
CVE-2025-30985
9.8

A PHP object injection vulnerability in GNUCommerce WordPress plugin allows attackers to execute arbitrary code through deserialization of untrusted d...

Apr 15, 2025
CVE-2025-3439
9.8

The Everest Forms WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'field_value' parameter. This a...

Apr 11, 2025
CVE-2025-32568
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the EmpikPlace for WooCommerce WordPress ...

Apr 11, 2025
CVE-2025-32375
EPSS 66.2% 9.8

CVE-2025-32375 is an insecure deserialization vulnerability in BentoML's runner server that allows remote code execution. Attackers can execute arbitr...

Apr 9, 2025
CVE-2025-27520
EPSS 77.8% 9.8

CVE-2025-27520 is a critical remote code execution vulnerability in BentoML caused by insecure deserialization in serde.py. It allows unauthenticated ...

Apr 4, 2025
CVE-2025-2244
9.8

This vulnerability allows remote attackers to execute arbitrary code on Bitdefender GravityZone Console servers by exploiting insecure PHP deserializa...

Apr 4, 2025
CVE-2025-31612
9.8

This vulnerability allows attackers to inject malicious PHP objects through deserialization of untrusted data in the CBX Poll WordPress plugin. Succes...

Apr 1, 2025
CVE-2025-30065
9.8

This vulnerability in Apache Parquet's parquet-avro module allows attackers to execute arbitrary code by exploiting schema parsing flaws. It affects a...

Apr 1, 2025
CVE-2025-31084
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in Sunshine Photo Cart WordPress plugin. Suc...

Apr 1, 2025
CVE-2025-2332
9.8

This CVE describes a PHP object injection vulnerability in the Export All Posts, Products, Orders, Refunds & Users WordPress plugin. Unauthenticated a...

Mar 27, 2025
CVE-2025-29310
9.8

A critical vulnerability in ONOS v2.7.0 allows attackers to execute arbitrary commands or access network information by sending a specially crafted LL...

Mar 24, 2025
CVE-2024-9701
9.8

This CVE describes a critical Remote Code Execution vulnerability in Kedro's ShelveStore class (version 0.19.8). Attackers can execute arbitrary Pytho...

Mar 20, 2025
CVE-2024-9053
9.8

CVE-2024-9053 is a critical remote code execution vulnerability in vLLM's AsyncEngineRPCServer where untrusted pickle data can be deserialized without...

Mar 20, 2025
CVE-2024-9070
9.8

A deserialization vulnerability in BentoML's runner server allows attackers to execute arbitrary code by manipulating the args-number parameter. This ...

Mar 20, 2025
CVE-2024-8502
9.8

This vulnerability allows remote attackers to execute arbitrary code on servers running modelscope/agentscope v0.0.6a3 by sending malicious serialized...

Mar 20, 2025
CVE-2024-12433
9.8

This CVE allows remote attackers to execute arbitrary code on systems running vulnerable versions of infiniflow/ragflow. Attackers can bypass authenti...

Mar 20, 2025
CVE-2024-12044
9.8

This critical vulnerability allows remote code execution in open-mmlab/mmdetection v3.3.0 through unsafe deserialization in distributed training. Atta...

Mar 20, 2025
CVE-2024-11041
9.8

CVE-2024-11041 is a critical remote code execution vulnerability in vLLM v0.6.2 where the MessageQueue.dequeue() function uses insecure pickle.loads()...

Mar 20, 2025
CVE-2024-10553
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on H2O-3 machine learning platforms by exploiting insecure deseri...

Mar 20, 2025
CVE-2024-10190
9.8

Horovod versions up to v0.28.1 are vulnerable to unauthenticated remote code execution via malicious pickle objects in PUT requests. Attackers can exe...

Mar 20, 2025
CVE-2025-27778
9.8

Applio versions 3.2.8-bugfix and prior contain an unsafe deserialization vulnerability in infer.py that allows remote attackers to execute arbitrary c...

Mar 19, 2025
CVE-2025-27780
9.8

This vulnerability allows remote attackers to execute arbitrary code on Applio voice conversion tool servers by exploiting unsafe deserialization in t...

Mar 19, 2025
CVE-2024-13410
9.8

This CVE describes a PHP Object Injection vulnerability in CozyStay and TinySalt WordPress plugins. Unauthenticated attackers can inject PHP objects v...

Mar 19, 2025
CVE-2024-13824
9.8

CVE-2024-13824 is a PHP object injection vulnerability in the CiyaShop WordPress theme that allows unauthenticated attackers to inject malicious PHP o...

Mar 14, 2025
CVE-2025-25940
9.8

CVE-2025-25940 is an insecure XML deserialization vulnerability in VisiCut 2.1 that allows remote code execution when processing malicious PLF files. ...

Mar 10, 2025
CVE-2025-27816
9.8

This vulnerability allows remote code execution on Arctera InfoScale servers through insecure deserialization of .NET remoting messages. Attackers can...

Mar 7, 2025

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 992 CVEs classified as CWE-502, with 479 rated critical and 457 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free