CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,991 vulnerabilities with CWE-502
CVE-2025-71376 HIGH
picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.AutoComplete.fetch_completions
CVSS 8.1
CVE-2025-71370 HIGH
picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execWrapper
CVSS 8.1
CVE-2025-71365 HIGH
picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Detection Bypass
CVSS 8.1
CVE-2025-71341 HIGH
picklescan - Remote Code Execution via Undetected profile.Profile.runctx
CVSS 8.1
CVE-2025-71358 HIGH
picklescan - Remote Code Execution via idlelib.autocomplete.AutoComplete.get_entity
CVSS 8.1
CVE-2025-71344 HIGH
picklescan - Arbitrary Code Execution via Undetected ensurepip._run_pip Function
CVSS 8.1
CVE-2025-71339 HIGH
Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_length Gadget
CVSS 8.1
CVE-2025-71378 HIGH
picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle Files
CVSS 8.1
CVE-2025-71357 HIGH
picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand
CVSS 8.1
CVE-2025-71348 HIGH
picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass
CVSS 8.1
CVE-2025-27511 HIGH
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVSS 7.2
CVE-2025-71321 CRITICAL
picklescan - Arbitrary File Writing via distutils Module Bypass
CVSS 9.8
CVE-2025-69130 HIGH
WordPress Entrepreneur - Booking for Small Businesses WordPress Theme theme <= 3.1.3 - PHP Object Injection vulnerability
CVSS 8.8
CVE-2025-69127 CRITICAL
WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-69111 CRITICAL
WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60236 CRITICAL
WordPress Creatify theme <= 1.5 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60231 CRITICAL
WordPress The Hospital theme <= 1.8.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60230 CRITICAL
WordPress The Barber Shop theme <= 1.9 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60229 CRITICAL
WordPress Lagom theme <= 2.0 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-69122 CRITICAL
WordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-69108 CRITICAL
WordPress Hot Coffee theme <= 1.7 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-60205 CRITICAL
WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2025-11993 HIGH
WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subscriber+) PHP Object Injection
CVSS 8.8
CVE-2025-33255 HIGH
NVIDIA TensorRT-LLM - Remote Code Execution via MPI Server Deserialization
CVSS 7.5
CVE-2025-51427 HIGH
ModelScope 1.25.0 - Remote Code Execution via Crafted Module in Configuration File
CVSS 7.3
Details
Vulnerabilities 2,991
Exploit Likelihood Medium