CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,741 vulnerabilities with CWE-502
CVE-2026-24141
HIGH
NVIDIA Model Optimizer < 0.41.0 - Deserialization of Untrusted Data in ONNX Quantization Feature
CVSS 7.8
CVE-2026-4735
HIGH
A stack overflow and DoS vulnerability in DTStack/chunjun
CVE-2026-4538
MEDIUM
PyTorch pt2 Loading deserialization
CVSS 5.3
CVE-2026-0677
MEDIUM
WordPress TotalContest Lite plugin <= 2.9.1 - PHP Object Injection vulnerability
CVSS 6.3
CVE-2026-29109
HIGH
SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter Processing
CVSS 7.2
CVE-2026-25445
HIGH
WordPress WishList Member X plugin <= 3.29.0 - PHP Object Injection vulnerability
CVSS 8.8
CVE-2026-27096
HIGH
WordPress ColorFolio - Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrusted data vulnerability
CVSS 8.1
CVE-2026-25873
CRITICAL
OmniGen2-RL Reward Server Unsafe Deserialization RCE
CVSS 9.8
CVE-2026-25449
CRITICAL
WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-25769
CRITICAL
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
CVSS 9.1
CVE-2026-1323
HIGH
Insecure Deserialization in extension "Mailqueue" (mailqueue)
CVSS 8.8
CVE-2026-32355
HIGH
Crocoblock JetEngine <3.8.4.1 - Deserialization
CVSS 8.8
CVE-2026-3060
CRITICAL
SGLang < 0.5.10 - Unauthenticated Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2026-3059
CRITICAL
SGLang Multimodal Module - Deserialization
CVSS 9.8
CVE-2026-3967
MEDIUM
Alfresco Activiti <7.19/8.8.0 - Deserialization
CVSS 6.3
CVE-2026-22248
HIGH
GLPI 11.0.0-11.0.4 - Authenticated RCE
CVSS 8.0
CVE-2026-2626
HIGH
Divi-Booster <5.0.2 - CSRF & Object Injection
CVSS 8.1
CVE-2026-26114
HIGH
Microsoft Office SharePoint - Deserialization
CVSS 8.8
CVE-2026-25166
HIGH
Windows System Image Manager - Deserialization
CVSS 7.8
CVE-2026-1286
HIGH
Unspecified Product - Deserialization
CVE-2026-27685
CRITICAL
SAP NetWeaver Enterprise Portal Administration - Deserialization of Untrusted Data via Malicious Content Upload
CVSS 9.1
CVE-2026-2020
HIGH
WordPress JS Archive List <=6.1.7 - Deserialization
CVSS 7.5
CVE-2026-28277
MEDIUM
LangGraph SQLite Checkpoint <=1.0.9 - Deserialization
CVSS 6.8
CVE-2026-27749
HIGH
Avira Internet Security - Deserialization
CVSS 7.8
CVE-2026-2599
CRITICAL
Database for Contact Form 7 <1.4.7 - Deserialization
CVSS 9.8
Details
Vulnerabilities
2,741
Exploit Likelihood
Medium