CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,813 vulnerabilities with CWE-502
CVE-2025-25691 MEDIUM
PrestaShop 8.2.0 - Remote Code Execution via PHAR Deserialization in Theme Import
CVSS 6.5
CVE-2025-53078 HIGH
Samsung Data Management Server Firmware >=2.0.0 <2.3.13.1 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.0
CVE-2025-8266 MEDIUM
chancms < 3.1.3 - Deserialization via getArticle Function
CVSS 6.3
CVE-2025-8227 MEDIUM
chancms < 3.1.3 - Deserialization via /collect/getArticle taskUrl Parameter
CVSS 6.3
CVE-2025-54366 HIGH
freescout < 1.8.86 - Authenticated Remote Code Execution via Unsafe Deserialization in Helper::decrypt()
CVSS 8.8
CVE-2025-26397 HIGH
SolarWinds Observability Self-Hosted < 2025.2.1 - Privilege Escalation via Untrusted Deserialization
CVSS 7.8
CVE-2025-4393 MEDIUM
Medtronic MyCareLink Patient Monitor <June 25, 2025 - Use After Free
CVSS 6.5
CVE-2025-43489 MEDIUM
Poly Clariti Manager <10.12.1 - Deserialization
CVSS 5.2
CVE-2025-7916 CRITICAL
WinMatrix3 < 3.8.52.5 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2025-7876 MEDIUM
MetaCRM < 6.4.2 - Remote Code Execution via Deserialization in download.jsp AnalyzeParam
CVSS 6.3
CVE-2025-53770 CRITICAL KEV
Microsoft SharePoint Server - Code Injection
CVSS 9.8
CVE-2025-7697 CRITICAL
Google Sheets Integration <=1.1.1 - Unauthenticated PHP Object Injection
CVSS 9.8
CVE-2025-7696 CRITICAL
WordPress Plugin <1.2.3 - Code Injection
CVSS 9.8
CVE-2025-7433 HIGH
Sophos Intercept X for Windows <2025.1 - Privilege Escalation
CVSS 8.8
CVE-2025-31422 HIGH
designthemes Visual Art | Gallery WP <2.4 - Code Injection
CVSS 8.8
CVE-2025-30973 CRITICAL
CoSchool LMS <1.4.3 - Object Injection
CVSS 9.8
CVE-2025-30949 CRITICAL
Guru Team Site Chat <1.0.4 - Code Injection
CVSS 9.8
CVE-2025-28961 CRITICAL
Md Yeasin Ul Haider URL Shortener <3.0.7 - Object Injection
CVSS 9.8
CVE-2025-24779 HIGH
NooTheme Yogi <2.9.0 - Code Injection
CVSS 8.8
CVE-2025-24777 HIGH
awethemes Hillter <3.0.7 - Object Injection
CVSS 8.8
CVE-2025-53990 HIGH
JetFormBuilder <3.5.1.2 - Object Injection
CVSS 7.2
CVE-2025-49841 CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via SoVITS_dropdown Input
CVSS 9.8
CVE-2025-49840 CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via GPT_dropdown Input
CVSS 9.8
CVE-2025-49839 CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via Model Path Input
CVSS 9.8
CVE-2025-49838 CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via AudioPreDeEcho Model Path
CVSS 9.8
Details
Vulnerabilities 2,813
Exploit Likelihood Medium