CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,813 vulnerabilities with CWE-502
CVE-2025-49837 CRITICAL
gpt-sovits-webui < 20250228v3 - Unsafe Deserialization via AudioPre Model Path
CVSS 9.8
CVE-2025-30761 MEDIUM
Oracle JDK and GraalVM Enterprise Edition - Unauthenticated Deserialization of Untrusted Data in Scripting Component
CVSS 5.9
CVE-2025-7504 HIGH
Friends WordPress Plugin 3.5.1 - Code Injection
CVSS 7.5
CVE-2025-30025 HIGH
Server Process - Privilege Escalation
CVSS 7.8
CVE-2025-30023 CRITICAL
AXIS Camera Station < 5.58.47195 & Pro < 6.9.47069 - Authenticated RCE via Untrusted Deserialization
CVSS 9.0
CVE-2025-6742 HIGH
SureForms <= 1.7.3 - Unauthenticated PHP Object Injection
CVSS 7.5
CVE-2025-7216 HIGH
lty628 Aidigu <1.8.2 - Deserialization
CVSS 7.3
CVE-2025-49533 CRITICAL
Adobe Experience Manager < 6.5.23.0 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2025-27203 CRITICAL
Adobe Connect <24.0 - Code Injection
CVSS 9.6
CVE-2025-47994 HIGH
Microsoft 365 Apps and Office - Privilege Escalation via Untrusted Data Deserialization
CVSS 7.8
CVE-2025-42980 CRITICAL
SAP NetWeaver Enterprise Portal Federated Portal Network - Deserial...
CVSS 9.1
CVE-2025-42966 CRITICAL
SAP NetWeaver XML Data Archiving Service - Deserialization
CVSS 9.1
CVE-2025-42964 CRITICAL
SAP NetWeaver Enterprise Portal - Code Injection
CVSS 9.1
CVE-2025-42963 CRITICAL
SAP NetWeaver Application server for Java Log Viewer - Use After Free
CVSS 9.1
CVE-2025-6811 CRITICAL
Mescius ActiveReports.NET - Deserialization
CVSS 9.8
CVE-2025-6810 CRITICAL
Mescius ActiveReports.NET - Remote Code Execution via ReadValue Deserialization
CVSS 9.8
CVE-2025-7099 MEDIUM
BoyunCMS < 1.21 - Deserialization via Install Handler db_host Argument
CVSS 5.6
CVE-2025-52828 HIGH
designthemes Red Art <3.7 - Code Injection
CVSS 8.8
CVE-2025-49417 CRITICAL
BestWpDeveloper WooCommerce Product Multi-Action <1.3 - Code Injection
CVSS 9.8
CVE-2025-43713 MEDIUM
ASNA Assist & Registrar <2025-03-31 - Deserialization
CVSS 6.5
CVE-2025-34067 CRITICAL
Hikvision Integrated Security Management Platform - RCE
CVE-2025-6464 HIGH
Forminator Forms < 1.44.3 - Unauthenticated PHP Object Injection via Entry Delete Upload Files
CVSS 7.5
CVE-2025-34060 CRITICAL
Monero Project's Laravel-based forum < - Code Injection
CVE-2025-53416 HIGH
Delta Electronics DTN Soft Project File Parsing - Deserialization
CVSS 7.8
CVE-2025-53415 HIGH
Delta Electronics DTM Soft Project File Parsing - Deserialization
CVSS 7.8
Details
Vulnerabilities 2,813
Exploit Likelihood Medium