CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,813 vulnerabilities with CWE-502
CVE-2025-55232
CRITICAL
Microsoft HPC Pack < 6.3.8352 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2025-54897
HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2025-53303
HIGH
ThemeMove Core <1.4.2 - Code Injection
CVSS 8.8
CVE-2025-48101
HIGH
Constant Contact for WordPress <4.1.1 - Code Injection
CVSS 8.8
CVE-2025-47579
CRITICAL
ThemeGoods Photography <= 7.7.2 - Unauthenticated PHP Object Injection via Deserialization
CVSS 9.0
CVE-2025-41701
HIGH
Engineering Tool <version> - Command Injection
CVSS 7.8
CVE-2025-42944
CRITICAL
SAP NetWeaver - Unauthenticated Remote Code Execution via RMI-P4 Deserialization
CVSS 10.0
CVE-2025-58757
HIGH
MONAI < 1.5.0 - Remote Code Execution via Pickle Deserialization
CVSS 8.8
CVE-2025-58756
HIGH
MONAI < 1.5.0 - Deserialization of Untrusted Data via Checkpoint Loading
CVSS 8.8
CVE-2025-58782
MEDIUM
Apache Jackrabbit Core/JCR Commons <2.22.1 - Deserialization
CVSS 6.5
CVE-2025-58839
HIGH
aThemeArt Translations eDS Responsive Menu <1.2 - Object Injection
CVSS 7.2
CVE-2025-58815
HIGH
Rubel Miah Aitasi Coming Soon <2.0.2 - Object Injection
CVSS 7.2
CVE-2025-48535
HIGH
Android - Local Privilege Escalation via Unsafe Deserialization in AppRestrictionsFragment
CVSS 7.8
CVE-2025-32312
HIGH
Android - Local Privilege Escalation via Unsafe Deserialization in PackageParser
CVSS 7.8
CVE-2025-9365
HIGH
Fuji Electric FRENIC-Loader 4 - Code Injection
CVSS 7.8
CVE-2025-53690
CRITICAL
KEV
Sitecore XM/X <9.0 - Code Injection
CVSS 9.0
CVE-2025-58644
HIGH
Enituretechnology LTL Freight Quotes - TQL Edition <1.2.6 - Code In...
CVSS 7.2
CVE-2025-58643
HIGH
enuiretechnology LTL Freight Quotes - Daylight Edition <2.2.7 - Cod...
CVSS 7.2
CVE-2025-58642
HIGH
Enituretechnology LTL Freight Quotes - Day & Ross Edition <2.1.11 -...
CVSS 7.2
CVE-2025-53691
HIGH
Sitecore XP 9.0-9.3, 10.0-10.4 - RCE via Untrusted Deserialization
CVSS 8.8
CVE-2025-58163
HIGH
FreeScout < 1.8.186 - Authenticated Remote Code Execution via Untrusted Data Deserialization in Decrypt Function
CVSS 8.8
CVE-2025-9260
MEDIUM
Fluent Forms <6.1.1 - Code Injection
CVSS 6.5
CVE-2025-7976
HIGH
Anritsu ShockLine < 2025.4.2 - Remote Code Execution via CHX File Deserialization
CVSS 7.8
CVE-2025-9188
HIGH
DASYLab - Remote Code Execution via Crafted DSB File Deserialization
CVSS 7.8
CVE-2025-5662
CRITICAL
h2oai/h2o-3 < 3.46.0.8 - Remote Code Execution via JDBC Connection Parameter Deserialization
CVSS 9.8
Details
Vulnerabilities
2,813
Exploit Likelihood
Medium