CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,769 vulnerabilities with CWE-502
CVE-2025-33213 HIGH
NVIDIA Merlin Transformers4Rec - Deserialization
CVSS 8.8
CVE-2025-67535 MEDIUM
WePlugins - WordPress Development Company WP Maps <4.8.6 - Code Inj...
CVSS 6.6
CVE-2025-66631 CRITICAL
CSLA .NET < 6.0.0 - Remote Code Execution via WcfProxy NetDataContractSerializer Deserialization
CVSS 9.8
CVE-2025-42928 CRITICAL
SAP jConnect - SDK for ASE 16.0.4-16.0.4, 16.1-16.1 - Remote Code Execution via Deserialization
CVSS 9.1
CVE-2025-63721 HIGH
HummerRisk < 1.5.0 - Authenticated Remote Code Execution via Snakeyaml Deserialization
CVSS 8.8
CVE-2025-66571 CRITICAL
UNA CMS <14.0.0-RC4 - Code Injection
CVE-2025-55182 CRITICAL KEV
React Server Components <19.2.0 - RCE
CVSS 10.0
CVE-2025-41700 HIGH
CODESYS < 3.5.21.40 - Unauthenticated Remote Code Execution via Malicious Project File
CVSS 7.8
CVE-2025-13805 LOW
NutzBoot < 2.6.0-SNAPSHOT - Remote Code Execution via LiteRpc-Serializer Deserialization
CVSS 3.7
CVE-2025-9191 MEDIUM
Houzez WordPress <4.1.6 - Code Injection
CVSS 6.3
CVE-2025-62703 HIGH
Fugue < 0.9.1 - Remote Code Execution via Pickle Deserialization
CVSS 8.8
CVE-2025-51746 CRITICAL
jishenghua JSH_ERP < 2.3.1 - Remote Code Execution via Fastjson Deserialization
CVSS 9.8
CVE-2025-51745 CRITICAL
jishenghua JSH_ERP < 2.3.1 - Deserialization of Untrusted Data via Fastjson
CVSS 9.8
CVE-2025-51744 CRITICAL
jishenghua JSH_ERP < 2.3.1 - Deserialization of Untrusted Data via Fastjson
CVSS 9.8
CVE-2025-51743 CRITICAL
jishenghua JSH_ERP < 2.3.1 - Remote Code Execution via Fastjson Deserialization
CVSS 9.8
CVE-2025-51742 CRITICAL
Jishenghua Jsherp < 2.3.1 - Insecure Deserialization
CVSS 9.8
CVE-2025-61168 CRITICAL
SIGB PMB <8.0.1.14 - Code Injection
CVSS 9.8
CVE-2025-13467 MEDIUM
Keycloak LDAP Federation < 26.4.6 - Authenticated Deserialization of Untrusted Data via LDAP Server Configuration
CVSS 5.5
CVE-2025-66073 HIGH
Cozmoslabs WP Webhooks <3.3.9 - Code Injection
CVSS 7.2
CVE-2025-66055 HIGH
Icegram Email Subscribers & Newsletters <6 - Code Injection
CVSS 7.2
CVE-2025-62164 HIGH
vLLM 0.10.2-0.11.1 - Remote Code Execution via Malicious Prompt Embedding Tensors
CVSS 8.8
CVE-2025-59245 CRITICAL
Microsoft SharePoint Online - Elevation of Privilege via Deserialization of Untrusted Data
CVSS 9.8
CVE-2025-36072 HIGH
IBM Webmethods Integration - Insecure Deserialization
CVSS 8.8
CVE-2025-64408 MEDIUM
Apache Causeway < 3.5.0 - Authenticated Remote Code Execution via URL Parameter Deserialization
CVSS 6.3
CVE-2025-13145 HIGH
WP Import - Ultimate CSV XML Importer - Code Injection
CVSS 7.2
Details
Vulnerabilities 2,769
Exploit Likelihood Medium