CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (994)
CVE-2021-21426 is an insecure deserialization vulnerability in Magento-LTS that allows remote code execution. Attackers can exploit this to execute ar...
Apr 21, 2021CVE-2021-21524 is a critical untrusted deserialization vulnerability in Dell SRM and SMR software that allows remote unauthenticated attackers to exec...
Apr 12, 2021Apache OFBiz versions before 17.12.06 contain an unsafe deserialization vulnerability in the SOAP component. Unauthenticated attackers can exploit thi...
Mar 22, 2021CVE-2020-36282 is a critical deserialization vulnerability in RabbitMQ JMS Client that allows remote code execution when processing malicious StreamMe...
Mar 12, 2021CVE-2020-29045 is a critical remote code execution vulnerability in the Food and Drink Menu WordPress plugin. Attackers can execute arbitrary code by ...
Mar 11, 2021This vulnerability allows remote attackers to execute arbitrary code on WordPress sites using the wp-hotel-booking plugin through version 1.10.2. Atta...
Mar 3, 2021CVE-2021-22855 is a critical deserialization vulnerability in the Soar Cloud System HR Portal that allows remote attackers to execute arbitrary comman...
Feb 17, 2021CVE-2021-27213 is a critical remote code execution vulnerability in pystemon's config.py file that allows attackers to execute arbitrary code via YAML...
Feb 14, 2021CVE-2020-27868 is a critical remote code execution vulnerability in Qognify Ocularis video management software. Unauthenticated attackers can exploit ...
Feb 12, 2021This vulnerability allows remote unauthenticated attackers to send malicious messages to SolarWinds Orion's Collector Service on TCP port 1801, which ...
Feb 3, 2021CVE-2021-3160 is an unauthenticated remote code execution vulnerability in ASSUWEB 359.3 build 1, a subcomponent of ACA ASSUREX RENTES insurance contr...
Jan 28, 2021CVE-2020-4682 is a critical remote code execution vulnerability in IBM MQ caused by unsafe deserialization of trusted data. Attackers can exploit this...
Jan 28, 2021CVE-2020-27583 is a critical Java deserialization vulnerability in IBM InfoSphere Information Server 8.5.0.0 that allows unauthenticated remote attack...
Jan 26, 2021CVE-2021-25294 is a critical remote code execution vulnerability in OpenCATS caused by unsafe deserialization of user input. Attackers can exploit thi...
Jan 18, 2021CVE-2020-24639 is a critical Java deserialization vulnerability in Airwave Glass that allows remote attackers to execute arbitrary commands. Successfu...
Jan 15, 2021This vulnerability allows remote attackers to execute arbitrary code on ThinkAdmin systems by exploiting insecure unserialize functions in specific AP...
Jan 13, 2021CVE-2020-11995 is a critical deserialization vulnerability in Apache Dubbo that allows remote attackers to execute arbitrary code by sending specially...
Jan 11, 2021This vulnerability allows unauthenticated remote attackers to execute arbitrary code with local administrator privileges on Proofpoint Insider Threat ...
Jan 6, 2021CVE-2020-10658 is a critical remote code execution vulnerability in Proofpoint Insider Threat Management Server (formerly ObserveIT Server) that allow...
Jan 6, 2021CVE-2021-3007 is a PHP deserialization vulnerability in Laminas Project's laminas-http component (and Zend Framework) that allows remote code executio...
Jan 4, 2021CVE-2019-7725 is a critical deserialization vulnerability in NukeViet CMS that allows remote code execution by exploiting the untrusted nvloginhash co...
Dec 31, 2020CVE-2020-22083 is a critical remote code execution vulnerability in jsonpickle versions through 1.4.1. It allows attackers to execute arbitrary code d...
Dec 17, 2020CVE-2020-5664 is a critical deserialization vulnerability in XooNIps that allows remote attackers to execute arbitrary code on affected systems. This ...
Nov 16, 2020CVE-2020-28032 is a critical deserialization vulnerability in WordPress that allows remote code execution. It affects WordPress sites before version 5...
Nov 2, 2020CVE-2020-24648 is a critical remote code execution vulnerability in HPE Intelligent Management Center (iMC) that allows attackers to execute arbitrary...
Oct 19, 2020This vulnerability allows remote attackers to execute arbitrary code on ARC Informatique PcVue web and mobile back-end servers by exploiting insecure ...
Oct 12, 2020This vulnerability allows remote attackers to execute arbitrary code on Hyland OnBase servers by sending specially crafted SOAP messages that exploit ...
Sep 11, 2020This vulnerability allows remote attackers to execute arbitrary code on Hyland OnBase systems due to unsafe JSON deserialization. Attackers can achiev...
Sep 11, 2020This vulnerability allows remote attackers to execute arbitrary code on IBM WebSphere Application Server by sending specially crafted serialized objec...
Aug 13, 2020CVE-2020-1948 is a critical deserialization vulnerability in Apache Dubbo that allows remote code execution. Attackers can send malicious RPC requests...
Jul 14, 2020This vulnerability allows remote attackers to execute arbitrary code on Atlassian Jira Server and Data Center instances through insecure deserializati...
Jul 3, 2020This vulnerability allows remote attackers to execute arbitrary commands on affected Cisco devices by sending crafted serialized Java objects. It affe...
Dec 15, 2015Adobe Connect versions 24.0 and earlier contain a deserialization vulnerability that allows attackers to execute arbitrary code on affected systems. E...
Jul 8, 2025The huggingface/transformers library contains a critical vulnerability allowing arbitrary code execution through malicious serialized checkpoints. Att...
Apr 10, 2024This CVE describes an unauthenticated PHP object injection vulnerability in the EnvíaloSimple WordPress plugin. Attackers can exploit deserialization...
Dec 29, 2023CVE-2023-42809 is a critical deserialization vulnerability in Redisson Java Redis client that allows remote code execution. Attackers who can redirect...
Oct 4, 2023This vulnerability in the Orchid Laravel package allows remote code execution through deserialization of untrusted data from the '_state' query parame...
Jul 11, 2023This vulnerability allows remote unauthenticated attackers to execute arbitrary code on McAfee Database Security servers by sending malicious Java ser...
Jun 2, 2021A serialization injection vulnerability in LangChain's dumps() and dumpd() functions allows attackers to inject malicious data that gets treated as le...
Dec 23, 2025This vulnerability allows an unauthorized attacker to execute arbitrary code on Microsoft Update Catalog webservers by exploiting insecure deserializa...
Dec 12, 2024This vulnerability allows arbitrary code execution when TensorFlow or Keras deserializes a malicious YAML model file. Attackers can exploit unsafe YAM...
Aug 12, 2021A buffer overflow vulnerability in scrcpy allows a compromised Android device to send crafted messages that cause memory corruption on the host system...
Dec 18, 2025A high-privileged user can exploit a deserialization vulnerability in SAP jConnect to execute arbitrary code remotely. This affects SAP systems using ...
Dec 9, 2025CVE-2025-55010 is an unsafe deserialization vulnerability in Kanboard that allows admin users to execute arbitrary PHP code by manipulating event data...
Aug 12, 2025SAP NetWeaver Enterprise Portal Federated Portal Network has a deserialization vulnerability where privileged users can upload malicious content. When...
Jul 8, 2025This vulnerability allows attackers to exploit insecure deserialization in Apache InLong's JDBC component, enabling arbitrary file reading on affected...
May 28, 2025The Uncanny Automator WordPress plugin contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code t...
May 14, 2025CVE-2025-42999 is a deserialization vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows privileged users to upload malicious ...
May 13, 2025This CVE describes a deserialization vulnerability in Adobe ColdFusion that allows attackers to execute arbitrary code without user interaction. Syste...
Apr 8, 2025This CVE describes a fastjson deserialization vulnerability in MSFM that allows remote code execution by sending malicious payloads to the system/tabl...
Jan 15, 2025About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free