CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,743 vulnerabilities with CWE-502
CVE-2026-22607 HIGH
fickling <= 0.1.6 - Incomplete List of Disallowed Inputs in cProfile Module Handling
CVSS 7.8
CVE-2026-22606 HIGH
fickling < 0.1.7 - Incomplete List of Disallowed Inputs in runpy Module Handling
CVSS 7.8
CVE-2026-22187 HIGH
openmicroscopy/bio-formats <= 8.3.0 - Deserialization of Untrusted Data via Memoization Cache Files
CVSS 7.8
CVE-2025-11993 HIGH
WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subscriber+) PHP Object Injection
CVSS 8.8
CVE-2025-33255 HIGH
NVIDIA TensorRT-LLM - Remote Code Execution via MPI Server Deserialization
CVSS 7.5
CVE-2025-69690 CRITICAL
Netgate pfSense CE 2.7.2 - Code Injection
CVSS 9.1
CVE-2025-60889 CRITICAL
StellarGroup HPX 1.11.0 - Deserialization
CVSS 9.8
CVE-2025-60887 MEDIUM
Cista <= 0.15 - Information Disclosure via Insecure Deserialization
CVSS 5.3
CVE-2025-62233 MEDIUM
Apache DolphinScheduler: Deserialization of untrusted data in RPC
CVSS 6.3
CVE-2025-62373 CRITICAL
Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer
CVSS 9.8
CVE-2025-15610 CRITICAL
OpenText RightFax through 25.4 - Deserialization
CVE-2025-33248 HIGH
NVIDIA Megatron LM < 0.15.3 - Remote Code Execution via Malicious File Loading
CVSS 7.8
CVE-2025-33247 HIGH
NVIDIA Megatron LM < 0.15.3 - Remote Code Execution via Quantization Configuration Loading
CVSS 7.8
CVE-2025-33244 CRITICAL
NVIDIA Apex - Deserialization of Untrusted Data
CVSS 9.0
CVE-2025-71260 HIGH
BMC FootPrints ITSM 20.20.02-20.24.01.001 - VIEWSTATE Deserialization Code Execution
CVSS 8.8
CVE-2025-60237 CRITICAL
WordPress Finag theme <= 1.5.0 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60233 CRITICAL
WordPress Zuut theme <= 1.4.2 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-54920 HIGH
Apache Spark <3.5.7/4.0.1 - Deserialization
CVSS 8.8
CVE-2025-13913 MEDIUM
Inductive Automation Ignition - Info Disclosure
CVSS 6.3
CVE-2025-56422 CRITICAL
LimeSurvey <6.15.0+250623 - Deserialization
CVSS 9.8
CVE-2025-11739 HIGH
Product Version - Deserialization
CVE-2025-54001 CRITICAL
ThemeREX Classter <=2.5 - Deserialization
CVSS 9.8
CVE-2025-57622 CRITICAL
Step-Video-T2V - Remote Code Execution via Pickle Deserialization in API Endpoints
CVSS 9.8
CVE-2025-52998 CRITICAL
Chamilo LMS < 1.11.30 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2025-50198 MEDIUM
Chamilo < 1.11.30 - Deserialization of Untrusted Data via Import Configuration Parameters
CVSS 4.9
Details
Vulnerabilities 2,743
Exploit Likelihood Medium