CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,741 vulnerabilities with CWE-502
CVE-2026-45247
CRITICAL
KEV
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
CVSS 9.8
CVE-2026-9497
MEDIUM
changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserialization
CVSS 6.3
CVE-2026-4372
HIGH
Arbitrary Remote Code Execution via `_attn_implementation_internal` Config Injection in huggingface/transformers
CVSS 7.8
CVE-2026-45659
HIGH
Microsoft SharePoint Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-41104
CRITICAL
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
CVSS 10.0
CVE-2026-9291
HIGH
Insecure Deserialization in Amazon Braket SDK Job Results Processing
CVSS 7.1
CVE-2026-39832
CRITICAL
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVSS 9.1
CVE-2026-8135
HIGH
Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.
CVSS 7.2
CVE-2026-48207
CRITICAL
Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement
CVSS 9.8
CVE-2026-24216
HIGH
NVIDIA BioNeMo Framework < commit dfd83a7 in Main - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-7637
CRITICAL
Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie
CVSS 9.8
CVE-2026-24163
HIGH
NVIDIA TensorRT-LLM < 1.2 - Remote Code Execution via Unsafe RPC Deserialization
CVSS 7.5
CVE-2026-24142
MEDIUM
NVIDIA TensorRT-LLM < 1.2 - Remote Code Execution via Unsafe Deserialization
CVSS 6.3
CVE-2026-6009
HIGH
Jaspersoft Library Deserialisation Vulnerability
CVE-2026-31072
CRITICAL
APScheduler - Remote Code Execution via Insecure Deserialization in JSONSerializer and CBORSerializer
CVSS 9.8
CVE-2026-43633
CRITICAL
HestiaCP 1.9.0-1.9.4 Deserialization RCE via Web Terminal
CVSS 10.0
CVE-2026-8727
HIGH
Remote Code Execution in extension "Site Crawler" (crawler)
CVE-2026-46725
CRITICAL
Remote Code Execution in extension "Content Element Selector" (ceselector)
CVE-2026-33233
HIGH
AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache Entries
CVSS 7.6
CVE-2026-26978
HIGH
Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupSplFileInfo.php
CVE-2026-7304
CRITICAL
SGLang - Unauthenticated Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2026-7301
CRITICAL
SGLang - Remote Code Execution
CVSS 9.8
CVE-2026-8751
HIGH
h2oai h2o-3 JAR Model.java importBinaryModel deserialization
CVSS 7.3
CVE-2026-8735
MEDIUM
Oinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserialization
CVSS 6.3
CVE-2026-8612
MEDIUM
WWW::Mechanize::Cached < 2.00 - Local Code Execution via Cache Response Forgery
CVSS 5.3
Details
Vulnerabilities
2,741
Exploit Likelihood
Medium