CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,769 vulnerabilities with CWE-502
CVE-2025-47552
CRITICAL
DZS Video Gallery <12.37 - Code Injection
CVSS 9.8
CVE-2025-47553
HIGH
DZS Video Gallery <12.25 - Code Injection
CVSS 8.8
CVE-2025-31047
HIGH
Themify Edmin <2.0.0 - Code Injection
CVSS 8.8
CVE-2025-15453
MEDIUM
Milvus < 2.6.8 - Deserialization via HTTP Endpoint Argument Manipulation
CVSS 6.3
CVE-2025-15438
MEDIUM
PluXml < 5.8.22 - Deserialization via FileCookieJar Destructor in Media Management Module
CVSS 4.7
CVE-2025-11157
HIGH
feast < 0.54.0 - Remote Code Execution via YAML Deserialization in Kubernetes Materializer
CVSS 7.8
CVE-2025-15276
HIGH
FontForge - Remote Code Execution via SFD File Parsing
CVSS 7.8
CVE-2025-15375
MEDIUM
EyouCMS < 1.7.8 - Remote Code Execution via Unserialize in arcpagelist Handler
CVSS 6.3
CVE-2025-15246
MEDIUM
aizuda snail-job <1.7.0 - Deserialization
CVSS 6.3
CVE-2025-15222
MEDIUM
Dromara Sa-Token <1.44.0 - Deserialization
CVSS 5.0
CVE-2025-15117
LOW
Dromara Sa-Token <1.44.0 - Deserialization
CVSS 3.1
CVE-2025-67729
HIGH
LMDeploy < 0.11.1 - Remote Code Execution via Insecure PyTorch Model Deserialization
CVSS 8.8
CVE-2025-68038
HIGH
Icegram Express Pro <6 - Code Injection
CVSS 7.2
CVE-2025-68665
HIGH
LangChain <0.3.80, 1.1.8 - Code Injection
CVSS 8.6
CVE-2025-68664
CRITICAL
LangChain <0.3.81 and 1.2.5 - Code Injection
CVSS 9.3
CVE-2025-13716
HIGH
Tencent MimicMotion - Deserialization
CVSS 7.8
CVE-2025-13715
HIGH
Tencent FaceDetection-DSFD - Deserialization
CVSS 7.8
CVE-2025-13714
HIGH
Tencent MedicalNet - Deserialization
CVSS 7.8
CVE-2025-13713
HIGH
Tencent Hunyuan3D-1 - Deserialization
CVSS 7.8
CVE-2025-13712
HIGH
Tencent HunyuanDiT - Use After Free
CVSS 7.8
CVE-2025-13711
HIGH
Tencent TFace < 2025-09-29 - Remote Code Execution via Untrusted Data Deserialization in Eval Endpoint
CVSS 7.8
CVE-2025-13710
HIGH
Tencent HunyuanVideo - Deserialization
CVSS 7.8
CVE-2025-13709
HIGH
Tencent TFace < 2025-09-29 - Remote Code Execution via restore_checkpoint Deserialization
CVSS 7.8
CVE-2025-13708
HIGH
Tencent NeuralNLP-NeuralClassifier - Use After Free
CVSS 7.8
CVE-2025-13707
HIGH
Tencent HunyuanDiT - Deserialization
CVSS 7.8
Details
Vulnerabilities
2,769
Exploit Likelihood
Medium