CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,741 vulnerabilities with CWE-502
CVE-2026-24141 HIGH
NVIDIA Model Optimizer < 0.41.0 - Deserialization of Untrusted Data in ONNX Quantization Feature
CVSS 7.8
CVE-2026-4735 HIGH
A stack overflow and DoS vulnerability in DTStack/chunjun
CVE-2026-4538 MEDIUM
PyTorch pt2 Loading deserialization
CVSS 5.3
CVE-2026-0677 MEDIUM
WordPress TotalContest Lite plugin <= 2.9.1 - PHP Object Injection vulnerability
CVSS 6.3
CVE-2026-29109 HIGH
SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter Processing
CVSS 7.2
CVE-2026-25445 HIGH
WordPress WishList Member X plugin <= 3.29.0 - PHP Object Injection vulnerability
CVSS 8.8
CVE-2026-27096 HIGH
WordPress ColorFolio - Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrusted data vulnerability
CVSS 8.1
CVE-2026-25873 CRITICAL
OmniGen2-RL Reward Server Unsafe Deserialization RCE
CVSS 9.8
CVE-2026-25449 CRITICAL
WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-25769 CRITICAL
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
CVSS 9.1
CVE-2026-1323 HIGH
Insecure Deserialization in extension "Mailqueue" (mailqueue)
CVSS 8.8
CVE-2026-32355 HIGH
Crocoblock JetEngine <3.8.4.1 - Deserialization
CVSS 8.8
CVE-2026-3060 CRITICAL
SGLang < 0.5.10 - Unauthenticated Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2026-3059 CRITICAL
SGLang Multimodal Module - Deserialization
CVSS 9.8
CVE-2026-3967 MEDIUM
Alfresco Activiti <7.19/8.8.0 - Deserialization
CVSS 6.3
CVE-2026-22248 HIGH
GLPI 11.0.0-11.0.4 - Authenticated RCE
CVSS 8.0
CVE-2026-2626 HIGH
Divi-Booster <5.0.2 - CSRF & Object Injection
CVSS 8.1
CVE-2026-26114 HIGH
Microsoft Office SharePoint - Deserialization
CVSS 8.8
CVE-2026-25166 HIGH
Windows System Image Manager - Deserialization
CVSS 7.8
CVE-2026-1286 HIGH
Unspecified Product - Deserialization
CVE-2026-27685 CRITICAL
SAP NetWeaver Enterprise Portal Administration - Deserialization of Untrusted Data via Malicious Content Upload
CVSS 9.1
CVE-2026-2020 HIGH
WordPress JS Archive List <=6.1.7 - Deserialization
CVSS 7.5
CVE-2026-28277 MEDIUM
LangGraph SQLite Checkpoint <=1.0.9 - Deserialization
CVSS 6.8
CVE-2026-27749 HIGH
Avira Internet Security - Deserialization
CVSS 7.8
CVE-2026-2599 CRITICAL
Database for Contact Form 7 <1.4.7 - Deserialization
CVSS 9.8
Details
Vulnerabilities 2,741
Exploit Likelihood Medium