CWE-502: Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

994
Total CVEs
480
Critical
458
High
8.8
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
83
2025
398
2024
223
2023
129
2022
34

Top Affected Vendors

1 Apache 57
2 Microsoft 35
3 Solarwinds 19
4 Ibm 16
5 Debian 14
6 Adobe 14
7 Oracle 12
8 Netapp 10
9 Givewp 9
10 Ivanti 9

All Deserialization of Untrusted Data CVEs (994)

CVE-2021-21426
9.8

CVE-2021-21426 is an insecure deserialization vulnerability in Magento-LTS that allows remote code execution. Attackers can exploit this to execute ar...

Apr 21, 2021
CVE-2021-21524
9.8

CVE-2021-21524 is a critical untrusted deserialization vulnerability in Dell SRM and SMR software that allows remote unauthenticated attackers to exec...

Apr 12, 2021
CVE-2021-26295
9.8

Apache OFBiz versions before 17.12.06 contain an unsafe deserialization vulnerability in the SOAP component. Unauthenticated attackers can exploit thi...

Mar 22, 2021
CVE-2020-36282
9.8

CVE-2020-36282 is a critical deserialization vulnerability in RabbitMQ JMS Client that allows remote code execution when processing malicious StreamMe...

Mar 12, 2021
CVE-2020-29045
9.8

CVE-2020-29045 is a critical remote code execution vulnerability in the Food and Drink Menu WordPress plugin. Attackers can execute arbitrary code by ...

Mar 11, 2021
CVE-2020-29047
9.8

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites using the wp-hotel-booking plugin through version 1.10.2. Atta...

Mar 3, 2021
CVE-2021-22855
9.8

CVE-2021-22855 is a critical deserialization vulnerability in the Soar Cloud System HR Portal that allows remote attackers to execute arbitrary comman...

Feb 17, 2021
CVE-2021-27213
9.8

CVE-2021-27213 is a critical remote code execution vulnerability in pystemon's config.py file that allows attackers to execute arbitrary code via YAML...

Feb 14, 2021
CVE-2020-27868
9.8

CVE-2020-27868 is a critical remote code execution vulnerability in Qognify Ocularis video management software. Unauthenticated attackers can exploit ...

Feb 12, 2021
CVE-2021-25274
9.8

This vulnerability allows remote unauthenticated attackers to send malicious messages to SolarWinds Orion's Collector Service on TCP port 1801, which ...

Feb 3, 2021
CVE-2021-3160
9.8

CVE-2021-3160 is an unauthenticated remote code execution vulnerability in ASSUWEB 359.3 build 1, a subcomponent of ACA ASSUREX RENTES insurance contr...

Jan 28, 2021
CVE-2020-4682
9.8

CVE-2020-4682 is a critical remote code execution vulnerability in IBM MQ caused by unsafe deserialization of trusted data. Attackers can exploit this...

Jan 28, 2021
CVE-2020-27583
9.8

CVE-2020-27583 is a critical Java deserialization vulnerability in IBM InfoSphere Information Server 8.5.0.0 that allows unauthenticated remote attack...

Jan 26, 2021
CVE-2021-25294
9.8

CVE-2021-25294 is a critical remote code execution vulnerability in OpenCATS caused by unsafe deserialization of user input. Attackers can exploit thi...

Jan 18, 2021
CVE-2020-24639
9.8

CVE-2020-24639 is a critical Java deserialization vulnerability in Airwave Glass that allows remote attackers to execute arbitrary commands. Successfu...

Jan 15, 2021
CVE-2020-23653
9.8

This vulnerability allows remote attackers to execute arbitrary code on ThinkAdmin systems by exploiting insecure unserialize functions in specific AP...

Jan 13, 2021
CVE-2020-11995
9.8

CVE-2020-11995 is a critical deserialization vulnerability in Apache Dubbo that allows remote attackers to execute arbitrary code by sending specially...

Jan 11, 2021
CVE-2020-10655
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with local administrator privileges on Proofpoint Insider Threat ...

Jan 6, 2021
CVE-2020-10658
9.8

CVE-2020-10658 is a critical remote code execution vulnerability in Proofpoint Insider Threat Management Server (formerly ObserveIT Server) that allow...

Jan 6, 2021
CVE-2021-3007
9.8

CVE-2021-3007 is a PHP deserialization vulnerability in Laminas Project's laminas-http component (and Zend Framework) that allows remote code executio...

Jan 4, 2021
CVE-2019-7725
9.8

CVE-2019-7725 is a critical deserialization vulnerability in NukeViet CMS that allows remote code execution by exploiting the untrusted nvloginhash co...

Dec 31, 2020
CVE-2020-22083
9.8

CVE-2020-22083 is a critical remote code execution vulnerability in jsonpickle versions through 1.4.1. It allows attackers to execute arbitrary code d...

Dec 17, 2020
CVE-2020-5664
9.8

CVE-2020-5664 is a critical deserialization vulnerability in XooNIps that allows remote attackers to execute arbitrary code on affected systems. This ...

Nov 16, 2020
CVE-2020-28032
9.8

CVE-2020-28032 is a critical deserialization vulnerability in WordPress that allows remote code execution. It affects WordPress sites before version 5...

Nov 2, 2020
CVE-2020-24648
9.8

CVE-2020-24648 is a critical remote code execution vulnerability in HPE Intelligent Management Center (iMC) that allows attackers to execute arbitrary...

Oct 19, 2020
CVE-2020-26867
9.8

This vulnerability allows remote attackers to execute arbitrary code on ARC Informatique PcVue web and mobile back-end servers by exploiting insecure ...

Oct 12, 2020
CVE-2020-25258
9.8

This vulnerability allows remote attackers to execute arbitrary code on Hyland OnBase servers by sending specially crafted SOAP messages that exploit ...

Sep 11, 2020
CVE-2020-25260
9.8

This vulnerability allows remote attackers to execute arbitrary code on Hyland OnBase systems due to unsafe JSON deserialization. Attackers can achiev...

Sep 11, 2020
CVE-2020-4589
9.8

This vulnerability allows remote attackers to execute arbitrary code on IBM WebSphere Application Server by sending specially crafted serialized objec...

Aug 13, 2020
CVE-2020-1948
9.8

CVE-2020-1948 is a critical deserialization vulnerability in Apache Dubbo that allows remote code execution. Attackers can send malicious RPC requests...

Jul 14, 2020
CVE-2020-14172
9.8

This vulnerability allows remote attackers to execute arbitrary code on Atlassian Jira Server and Data Center instances through insecure deserializati...

Jul 3, 2020
CVE-2015-6420
9.8

This vulnerability allows remote attackers to execute arbitrary commands on affected Cisco devices by sending crafted serialized Java objects. It affe...

Dec 15, 2015
CVE-2025-27203
EPSS 13.4% 9.6

Adobe Connect versions 24.0 and earlier contain a deserialization vulnerability that allows attackers to execute arbitrary code on affected systems. E...

Jul 8, 2025
CVE-2024-3568
9.6

The huggingface/transformers library contains a critical vulnerability allowing arbitrary code execution through malicious serialized checkpoints. Att...

Apr 10, 2024
CVE-2023-51414
9.6

This CVE describes an unauthenticated PHP object injection vulnerability in the EnvíaloSimple WordPress plugin. Attackers can exploit deserialization...

Dec 29, 2023
CVE-2023-42809
9.6

CVE-2023-42809 is a critical deserialization vulnerability in Redisson Java Redis client that allows remote code execution. Attackers who can redirect...

Oct 4, 2023
CVE-2023-36825
9.6

This vulnerability in the Orchid Laravel package allows remote code execution through deserialization of untrusted data from the '_state' query parame...

Jul 11, 2023
CVE-2021-23894
9.6

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on McAfee Database Security servers by sending malicious Java ser...

Jun 2, 2021
CVE-2025-68664
9.3

A serialization injection vulnerability in LangChain's dumps() and dumpd() functions allows attackers to inject malicious data that gets treated as le...

Dec 23, 2025
CVE-2024-49147
9.3

This vulnerability allows an unauthorized attacker to execute arbitrary code on Microsoft Update Catalog webservers by exploiting insecure deserializa...

Dec 12, 2024
CVE-2021-37678
9.3

This vulnerability allows arbitrary code execution when TensorFlow or Keras deserializes a malicious YAML model file. Attackers can exploit unsafe YAM...

Aug 12, 2021
CVE-2025-34449
9.1

A buffer overflow vulnerability in scrcpy allows a compromised Android device to send crafted messages that cause memory corruption on the host system...

Dec 18, 2025
CVE-2025-42928
9.1

A high-privileged user can exploit a deserialization vulnerability in SAP jConnect to execute arbitrary code remotely. This affects SAP systems using ...

Dec 9, 2025
CVE-2025-55010
9.1

CVE-2025-55010 is an unsafe deserialization vulnerability in Kanboard that allows admin users to execute arbitrary PHP code by manipulating event data...

Aug 12, 2025
CVE-2025-42980
9.1

SAP NetWeaver Enterprise Portal Federated Portal Network has a deserialization vulnerability where privileged users can upload malicious content. When...

Jul 8, 2025
CVE-2025-27528
9.1

This vulnerability allows attackers to exploit insecure deserialization in Apache InLong's JDBC component, enabling arbitrary file reading on affected...

May 28, 2025
CVE-2025-3623
9.1

The Uncanny Automator WordPress plugin contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code t...

May 14, 2025
CVE-2025-42999
KEV EPSS 65.7% 9.1

CVE-2025-42999 is a deserialization vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows privileged users to upload malicious ...

May 13, 2025
CVE-2025-24447
EPSS 28.4% 9.1

This CVE describes a deserialization vulnerability in Adobe ColdFusion that allows attackers to execute arbitrary code without user interaction. Syste...

Apr 8, 2025
CVE-2024-57763
9.1

This CVE describes a fastjson deserialization vulnerability in MSFM that allows remote code execution by sending malicious payloads to the system/tabl...

Jan 15, 2025

About Deserialization of Untrusted Data (CWE-502)

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.

External reference: View CWE-502 on MITRE CWE →

Monitor Deserialization of Untrusted Data Vulnerabilities

Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.

Start Monitoring Free