CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,816 vulnerabilities with CWE-502
CVE-2025-27287 CRITICAL
SS Quiz <= 2.0.5 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.8
CVE-2025-27286 CRITICAL
Saoshyant Slider <3.0 - Code Injection
CVSS 9.8
CVE-2025-39565 MEDIUM
MelaPress Login Security <= 2.1.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 6.6
CVE-2025-3677 MEDIUM
lm-sys fastchat <0.2.36 - Deserialization
CVSS 5.3
CVE-2025-30985 CRITICAL
GNUCommerce <1.5.4 - Code Injection
CVSS 9.8
CVE-2025-3622 MEDIUM
Xorbits Inference <1.4.1 - Deserialization
CVSS 5.5
CVE-2025-3590 MEDIUM
Adianti Framework <8.0 - Deserialization
CVSS 6.3
CVE-2025-31935 MEDIUM
Subnet Solutions PowerSYSTEM Center - DoS
CVSS 6.2
CVE-2025-3439 CRITICAL
Everest Forms < 3.1.1 - Unauthenticated PHP Object Injection via Field Value Parameter
CVSS 9.8
CVE-2025-31932 HIGH
BizRobo! - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2025-32607 CRITICAL
WpBookingly <1.2.0 - Object Injection
CVSS 9.8
CVE-2025-32569 CRITICAL
TableOn - WordPress Posts Table Filterable <1.0.2 - Code Injection
CVSS 9.8
CVE-2025-32568 CRITICAL
Empik Place for Woocommerce <1.4.2 - Object Injection
CVSS 9.8
CVE-2025-32144 HIGH
PickPlugins Job Board Manager <2.1.60 - Object Injection
CVSS 8.8
CVE-2025-32143 HIGH
PickPlugins Accordion <2.3.10 - Code Injection
CVSS 8.8
CVE-2025-32145 HIGH
WpEvently <= 4.3.6 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.8
CVE-2025-32375 CRITICAL
BentoML < 1.4.8 - Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2025-30285 HIGH
ColdFusion <2023.12, 2021.18, 2025.0 - Deserialization
CVSS 8.4
CVE-2025-30284 HIGH
ColdFusion <2023.12, 2021.18, 2025.0 - Deserialization
CVSS 8.4
CVE-2025-24447 CRITICAL
ColdFusion 2023.12 2021.18 2025.0 and earlier - Deserialization of Untrusted Data
CVSS 9.1
CVE-2025-29793 HIGH
Microsoft SharePoint Enterprise Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2025-3413 MEDIUM
opplus springboot-admin - Deserialization of Untrusted Data via SysGeneratorController Tables Argument
CVSS 6.3
CVE-2025-3425 HIGH
IntelliSpace Portal <12 - Deserialization
CVE-2025-2251 MEDIUM
Red Hat JBoss EAP 7.4.23 - Unauthenticated Remote Code Execution via Marshalling Deserialization
CVSS 6.2
CVE-2025-31175 HIGH
Huawei EMUI and HarmonyOS - Deserialization of Untrusted Data in DSoftBus Module
CVSS 8.4
Details
Vulnerabilities 2,816
Exploit Likelihood Medium