CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,812 vulnerabilities with CWE-502
CVE-2025-10950 MEDIUM
geyang ml-logger < acf255bade5be6ad88d90735c8367b28cbe3a743 - Remote Code Execution via Deserialization in Ping Handler
CVSS 6.3
CVE-2025-56816 HIGH
Datart 1.0.0-rc.3 - Directory Traversal and Remote Code Execution via YAML Deserialization
CVSS 8.8
CVE-2025-48459 MEDIUM
Apache IoTDB <2.0.5 - Deserialization
CVSS 5.3
CVE-2025-26399 CRITICAL KEV
SolarWinds Web Help Desk < 12.8.6 - Unauthenticated Remote Code Execution via AjaxProxy Deserialization
CVSS 9.8
CVE-2025-58662 HIGH
Awesome Support <6.3.4 - Code Injection
CVSS 7.2
CVE-2025-57919 HIGH
ConveyThis Language Translate Widget <264 - Code Injection
CVSS 7.2
CVE-2025-53465 HIGH
raoinfotech GSheets Connector <1.1.1 - Code Injection
CVSS 7.2
CVE-2025-10771 MEDIUM
jeecg/jimureport < 2.1.2 - Remote Code Execution via DB2 JDBC Handler Deserialization
CVSS 6.3
CVE-2025-10770 MEDIUM
jeecg/jimureport < 2.1.2 - Deserialization via MySQL JDBC Handler
CVSS 6.3
CVE-2025-10769 MEDIUM
h2o 3.0.0.2-3.46.0.8 - Deserialization via ImportSQLTable Connection URL
CVSS 6.3
CVE-2025-10768 MEDIUM
h2o 3.0.0.2-3.46.0.8 - Deserialization via IBMDB2 JDBC Driver Connection URL
CVSS 6.3
CVE-2025-6544 CRITICAL
h2oai/h2o-3 <= 3.46.0.8 - Remote Code Execution via JDBC Connection Parameter Deserialization
CVSS 9.8
CVE-2025-9906 HIGH
Keras 3.0.0-3.10.9 - Remote Code Execution via Model.load_model Deserialization
CVSS 7.3
CVE-2025-59713 MEDIUM
Snipe-IT < 8.1.18 - Unauthenticated Deserialization of Untrusted Data
CVSS 6.8
CVE-2025-10035 CRITICAL KEV
Fortra GoAnywhere MFT < 7.6.3 - Deserialization of Untrusted Data via License Servlet
CVSS 10.0
CVE-2025-9083 CRITICAL
Ninja Forms <3.11.1 - Code Injection
CVSS 9.8
CVE-2025-59050 HIGH
Greenshot < 1.3.301 - Unauthenticated Remote Code Execution via WM_COPYDATA Message Deserialization
CVSS 8.4
CVE-2025-10492 CRITICAL
Cloud Jasperreports IO < 4.0.0 - Insecure Deserialization
CVSS 9.8
CVE-2025-59328 MEDIUM
Apache Fory < 0.12.2 - Denial of Service via Insecure Deserialization
CVSS 6.5
CVE-2025-58748 CRITICAL
Dataease < 2.10.13 - Remote Code Execution via H2 JDBC URL Deserialization
CVSS 9.8
CVE-2025-58046 CRITICAL
Dataease <= 2.10.12 - Remote Code Execution via Impala JDBC Connection String JNDI Injection
CVSS 9.8
CVE-2025-10433 MEDIUM
1Panel-dev MaxKB <2.0.2/2.1.0 - Deserialization
CVSS 6.3
CVE-2025-10252 LOW
SEAT Queue Ticket Kiosk <20250827 - Deserialization
CVSS 3.1
CVE-2025-10164 HIGH
sglang - Remote Code Execution via Pickle Deserialization
CVSS 7.3
CVE-2025-55232 CRITICAL
Microsoft HPC Pack < 6.3.8352 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
Details
Vulnerabilities 2,812
Exploit Likelihood Medium