CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,813 vulnerabilities with CWE-502
CVE-2025-25691
MEDIUM
PrestaShop 8.2.0 - Remote Code Execution via PHAR Deserialization in Theme Import
CVSS 6.5
CVE-2025-53078
HIGH
Samsung Data Management Server Firmware >=2.0.0 <2.3.13.1 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.0
CVE-2025-8266
MEDIUM
chancms < 3.1.3 - Deserialization via getArticle Function
CVSS 6.3
CVE-2025-8227
MEDIUM
chancms < 3.1.3 - Deserialization via /collect/getArticle taskUrl Parameter
CVSS 6.3
CVE-2025-54366
HIGH
freescout < 1.8.86 - Authenticated Remote Code Execution via Unsafe Deserialization in Helper::decrypt()
CVSS 8.8
CVE-2025-26397
HIGH
SolarWinds Observability Self-Hosted < 2025.2.1 - Privilege Escalation via Untrusted Deserialization
CVSS 7.8
CVE-2025-4393
MEDIUM
Medtronic MyCareLink Patient Monitor <June 25, 2025 - Use After Free
CVSS 6.5
CVE-2025-43489
MEDIUM
Poly Clariti Manager <10.12.1 - Deserialization
CVSS 5.2
CVE-2025-7916
CRITICAL
WinMatrix3 < 3.8.52.5 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2025-7876
MEDIUM
MetaCRM < 6.4.2 - Remote Code Execution via Deserialization in download.jsp AnalyzeParam
CVSS 6.3
CVE-2025-53770
CRITICAL
KEV
Microsoft SharePoint Server - Code Injection
CVSS 9.8
CVE-2025-7697
CRITICAL
Google Sheets Integration <=1.1.1 - Unauthenticated PHP Object Injection
CVSS 9.8
CVE-2025-7696
CRITICAL
WordPress Plugin <1.2.3 - Code Injection
CVSS 9.8
CVE-2025-7433
HIGH
Sophos Intercept X for Windows <2025.1 - Privilege Escalation
CVSS 8.8
CVE-2025-31422
HIGH
designthemes Visual Art | Gallery WP <2.4 - Code Injection
CVSS 8.8
CVE-2025-30973
CRITICAL
CoSchool LMS <1.4.3 - Object Injection
CVSS 9.8
CVE-2025-30949
CRITICAL
Guru Team Site Chat <1.0.4 - Code Injection
CVSS 9.8
CVE-2025-28961
CRITICAL
Md Yeasin Ul Haider URL Shortener <3.0.7 - Object Injection
CVSS 9.8
CVE-2025-24779
HIGH
NooTheme Yogi <2.9.0 - Code Injection
CVSS 8.8
CVE-2025-24777
HIGH
awethemes Hillter <3.0.7 - Object Injection
CVSS 8.8
CVE-2025-53990
HIGH
JetFormBuilder <3.5.1.2 - Object Injection
CVSS 7.2
CVE-2025-49841
CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via SoVITS_dropdown Input
CVSS 9.8
CVE-2025-49840
CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via GPT_dropdown Input
CVSS 9.8
CVE-2025-49839
CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via Model Path Input
CVSS 9.8
CVE-2025-49838
CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via AudioPreDeEcho Model Path
CVSS 9.8
Details
Vulnerabilities
2,813
Exploit Likelihood
Medium