CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

994
Total CVEs
480
Critical
458
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 57
2 Microsoft 35
3 Solarwinds 19
4 Ibm 16
5 Debian 14
6 Adobe 14
7 Oracle 12
8 Netapp 10
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (994)

CVE-2024-47636
9.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in the Eyecix JobSearc...

Oct 10, 2024
CVE-2024-22399
9.8

This vulnerability allows attackers to execute arbitrary code on Apache Seata servers by sending malicious serialized data when authentication is disa...

Sep 16, 2024
CVE-2024-29847
9.8

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti EPM systems by exploiting insecure deserializa...

Sep 12, 2024
CVE-2024-44902
9.8

A deserialization vulnerability in ThinkPHP versions 6.1.3 through 8.0.4 allows attackers to execute arbitrary code by sending specially crafted reque...

Sep 9, 2024
CVE-2024-40711
9.8

CVE-2024-40711 is a critical deserialization vulnerability in Veeam Backup & Replication that allows unauthenticated attackers to execute arbitrary co...

Sep 7, 2024
CVE-2024-8255
9.8

Delta Electronics DTN Soft version 2.0.1 and earlier contain a deserialization vulnerability that allows remote attackers to execute arbitrary code by...

Aug 29, 2024
CVE-2024-43931
9.8

This vulnerability allows remote attackers to execute arbitrary code through PHP object injection via deserialization of untrusted data in the eyecix ...

Aug 29, 2024
CVE-2024-8030
9.8

This vulnerability allows unauthenticated attackers to perform PHP object injection via deserialization of untrusted input in the Ultimate Store Kit p...

Aug 28, 2024
CVE-2024-5335
9.8

This vulnerability allows unauthenticated attackers to perform PHP object injection via a manipulated cookie in the Ultimate Store Kit plugin suite fo...

Aug 21, 2024
CVE-2024-43354
9.8

CVE-2024-43354 is a PHP object injection vulnerability in the myCred WordPress plugin that allows attackers to execute arbitrary code through deserial...

Aug 19, 2024
CVE-2024-28986
9.8

CVE-2024-28986 is a Java deserialization vulnerability in SolarWinds Web Help Desk that could allow remote code execution on the host system. While So...

Aug 13, 2024
CVE-2024-43141
9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Participants Database WordPress plugi...

Aug 13, 2024
CVE-2024-6793
9.8

This vulnerability allows remote attackers to execute arbitrary code on NI VeriStand DataLogging Server by sending specially crafted messages that tri...

Jul 22, 2024
CVE-2024-40624
9.8

This vulnerability in TorrentPier allows remote code execution by deserializing malicious cookies. Attackers can write arbitrary PHP files and execute...

Jul 15, 2024
CVE-2024-5488
9.8

CVE-2024-5488 is a critical vulnerability in the SEOPress WordPress plugin that allows unauthenticated attackers to exploit insecure REST API endpoint...

Jul 9, 2024
CVE-2024-5871
9.8

The WooCommerce Social Login plugin for WordPress is vulnerable to PHP object injection via deserialization of untrusted input in the 'woo_slg_verify'...

Jun 15, 2024
CVE-2024-5671
9.8

CVE-2024-5671 is an insecure deserialization vulnerability in Trellix IPS Manager workflows that allows unauthenticated remote attackers to execute ar...

Jun 14, 2024
CVE-2024-26289
9.8

CVE-2024-26289 is a critical deserialization vulnerability in PMB Services PMB that allows remote attackers to execute arbitrary code by sending malic...

May 27, 2024
CVE-2024-26579
9.8

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls using malicious parameters. Atta...

May 8, 2024
CVE-2023-51576
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Voltronic Power ViewPower systems. The ...

May 3, 2024
CVE-2023-39475
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Inductive Automation Ignition installat...

May 3, 2024
CVE-2024-1813
9.8

The Simple Job Board WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input, allowing unauthenticated attackers...

Apr 9, 2024
CVE-2024-31224
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of GPT Academic by sending malicious seria...

Apr 8, 2024
CVE-2023-51570
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Voltronic Power ViewPower Pro installat...

Apr 1, 2024
CVE-2024-29433
9.8

This vulnerability in Alldata v0.4.6 allows remote attackers to execute arbitrary code by sending specially crafted data to the FASTJSON deserializati...

Apr 1, 2024
CVE-2024-31094
9.8

This CVE describes a PHP object injection vulnerability in the WordPress Filter Custom Fields & Taxonomies Light plugin. Attackers can exploit insecur...

Mar 31, 2024
CVE-2024-28861
9.8

CVE-2024-28861 is a remote code execution vulnerability in Symfony 1 framework due to unsafe deserialization in the sfNamespacedParameterHolder class....

Mar 22, 2024
CVE-2024-2054
9.8

CVE-2024-2054 is a critical remote code execution vulnerability in Artica-Proxy's administrative web interface. Unauthenticated attackers can exploit ...

Mar 21, 2024
CVE-2024-28211
9.8

CVE-2024-28211 is a critical vulnerability in nGrinder versions before 3.5.9 that allows remote attackers to execute arbitrary code by connecting to m...

Mar 7, 2024
CVE-2024-28213
9.8

nGrinder versions before 3.5.9 contain a Java deserialization vulnerability that allows unauthenticated remote attackers to execute arbitrary code by ...

Mar 7, 2024
CVE-2024-24302
9.8

This vulnerability in the Tunis Soft 'Product Designer' module for PrestaShop allows remote attackers to execute arbitrary code, escalate privileges, ...

Mar 3, 2024
CVE-2024-23052
9.8

This vulnerability allows remote attackers to execute arbitrary code on WuKongCRM systems by exploiting a deserialization flaw in the fastjson compone...

Feb 29, 2024
CVE-2023-51518
9.8

Apache James email servers prior to versions 3.7.5 and 3.8.0 have a pre-authentication deserialization vulnerability in their JMX endpoint. Attackers ...

Feb 27, 2024
CVE-2024-24797
9.8

This vulnerability allows unauthenticated attackers to perform PHP object injection via deserialization of untrusted data in the ERE Recently Viewed W...

Feb 12, 2024
CVE-2024-22320
9.8

CVE-2024-22320 is an unsafe deserialization vulnerability in IBM Operational Decision Manager 8.10.3 that allows authenticated remote attackers to exe...

Feb 2, 2024
CVE-2024-23636
9.8

CVE-2024-23636 is a critical deserialization vulnerability in SOFARPC that allows remote code execution by bypassing the SOFA Hessian protocol's black...

Jan 23, 2024
CVE-2017-20189
9.8

This vulnerability in Clojure allows remote code execution through deserialization of untrusted objects. Attackers can craft malicious serialized obje...

Jan 22, 2024
CVE-2023-6049
9.8

The Estatik Real Estate WordPress plugin before version 4.1.1 contains a PHP Object Injection vulnerability via cookie deserialization. Unauthenticate...

Jan 15, 2024
CVE-2023-49442
9.8

This vulnerability allows remote attackers to execute arbitrary code on JEECG systems by sending specially crafted POST requests to the jeecgFormDemoC...

Jan 3, 2024
CVE-2023-32242
9.8

CVE-2023-32242 is a PHP object injection vulnerability in the WoodMart WordPress theme that allows attackers to execute arbitrary code through deseria...

Dec 21, 2023
CVE-2023-51656
9.8

This CVE describes a deserialization vulnerability in Apache IoTDB that allows attackers to execute arbitrary code by sending malicious serialized dat...

Dec 21, 2023
CVE-2023-29234
9.8

This CVE describes a deserialization vulnerability in Apache Dubbo that allows remote code execution when processing malicious packages. Attackers can...

Dec 15, 2023
CVE-2023-48887
9.8

CVE-2023-48887 is a critical deserialization vulnerability in Jupiter v1.3.1 that allows remote attackers to execute arbitrary commands by sending spe...

Dec 1, 2023
CVE-2023-47207
9.8

This critical vulnerability in Delta Electronics InfraSuite Device Master allows unauthenticated attackers to execute arbitrary code with local admini...

Nov 30, 2023
CVE-2023-44350
9.8

This vulnerability allows attackers to execute arbitrary code on Adobe ColdFusion servers by sending maliciously crafted data that gets improperly des...

Nov 17, 2023
CVE-2023-44353
9.8

This vulnerability allows attackers to execute arbitrary code on Adobe ColdFusion servers by sending maliciously crafted data that gets improperly des...

Nov 17, 2023
CVE-2023-47248
9.8

This vulnerability allows arbitrary code execution when PyArrow processes untrusted Arrow IPC, Feather, or Parquet files. Applications that read these...

Nov 9, 2023
CVE-2023-46817
9.8

CVE-2023-46817 is a PHP object injection vulnerability in phpFox that allows remote, unauthenticated attackers to execute arbitrary PHP code by exploi...

Nov 3, 2023
CVE-2023-47204
9.8

CVE-2023-47204 is a critical remote code execution vulnerability in transmute-core's YAML deserialization. Attackers can execute arbitrary Python code...

Nov 2, 2023
CVE-2023-35084
9.8

CVE-2023-35084 is a critical remote code execution vulnerability in Ivanti Endpoint Manager (formerly LANDesk Management Suite) caused by unsafe deser...

Oct 18, 2023

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free