CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,594 vulnerabilities with CWE-502
CVE-2026-0726 HIGH
Nexter Extension - Site Enhancements Toolkit <4.4.6 - Code Injection
CVSS 8.1
CVE-2026-0895 MEDIUM
Cpsit Typo3-mailqueue < 0.4.3 - Insecure Deserialization
CVE-2026-23746 CRITICAL
Entrust Instant Financial Issuance (IFI) On Premise <6.10.5-6.11.1 ...
CVE-2026-21226 HIGH
Azure Core < - Code Injection
CVSS 7.5
CVE-2026-20963 CRITICAL KEV
Microsoft Office SharePoint - Code Injection
CVSS 9.8
CVE-2026-0859 HIGH
Typo3 < 10.4.55 - Insecure Deserialization
CVSS 7.8
CVE-2026-22612 HIGH
Trailofbits Fickling < 0.1.7 - Insecure Deserialization
CVSS 7.8
CVE-2026-22609 HIGH
Fickling <0.1.7 - Code Injection
CVSS 7.8
CVE-2026-22608 HIGH
Fickling <0.1.7 - RCE
CVSS 7.8
CVE-2026-22607 HIGH
Fickling <0.1.6 - Code Injection
CVSS 7.8
CVE-2026-22606 HIGH
Fickling <0.1.6 - Code Injection
CVSS 7.8
CVE-2026-22187 HIGH
OME Pom-bio-formats - Insecure Deserialization
CVSS 7.8
CVE-2025-60887 MEDIUM
Cista <=0.15 - Info Disclosure
CVSS 5.3
CVE-2025-62233 MEDIUM
Apache DolphinScheduler: Deserialization of untrusted data in RPC
CVSS 6.3
CVE-2025-62373 CRITICAL
Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer
CVSS 9.8
CVE-2025-15610 CRITICAL
OpenText RightFax through 25.4 - Deserialization
CVE-2025-33248 HIGH
Nvidia Megatron LM - Information Disclosure
CVSS 7.8
CVE-2025-33247 HIGH
Nvidia Megatron LM - Remote Code Execution
CVSS 7.8
CVE-2025-33244 CRITICAL
Nvidia Apex - Denial of Service
CVSS 9.0
CVE-2025-71260 HIGH
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
CVSS 8.8
CVE-2025-60237 CRITICAL
WordPress Finag theme <= 1.5.0 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60233 CRITICAL
WordPress Zuut theme <= 1.4.2 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-54920 HIGH
Apache Spark <3.5.7/4.0.1 - Deserialization
CVSS 8.8
CVE-2025-13913 MEDIUM
Inductive Automation Ignition - Info Disclosure
CVSS 6.3
CVE-2025-56422 CRITICAL
LimeSurvey <6.15.0+250623 - Deserialization
CVSS 9.8
Details
Vulnerabilities 2,594
Exploit Likelihood Medium