CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,816 vulnerabilities with CWE-502
CVE-2025-3250
MEDIUM
elunez eladmin 2.7 - Deserialization
CVSS 4.3
CVE-2025-27520
CRITICAL
BentoML >=1.3.4 <1.4.3 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2025-2244
CRITICAL
Bitdefender GravityZone < 6.41.2-1 - Remote Code Execution via PHP Deserialization in Emails.php
CVSS 9.8
CVE-2025-3165
MEDIUM
thu-pacman chitu <0.1.0 - Deserialization
CVSS 5.3
CVE-2025-3162
MEDIUM
InternLM LMDeploy < 0.7.1 - Deserialization in PT File Handler
CVSS 5.3
CVE-2025-30889
HIGH
PickPlugins Testimonial Slider <2.0.13 - Code Injection
CVSS 8.8
CVE-2025-31612
CRITICAL
Sabuj Kundu CBX Poll <1.2.7 - Object Injection
CVSS 9.8
CVE-2025-30892
HIGH
WpTravelly <= 1.8.7 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.8
CVE-2025-27130
HIGH
Welcart e-Commerce <2.11.6 - Code Injection
CVSS 8.8
CVE-2025-30065
CRITICAL
Apache Parquet Java < 1.15.1 - Remote Code Execution via Schema Parsing
CVSS 9.8
CVE-2025-31087
CRITICAL
Multiple Shipping And Billing Address For Woocommerce <1.5 - Code I...
CVSS 9.8
CVE-2025-31084
CRITICAL
Sunshine Photo Cart <= 3.4.10 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.8
CVE-2025-31074
HIGH
MDJM Event Management <1.7.5.2 - Object Injection
CVSS 8.8
CVE-2025-31129
HIGH
jooby-pac4j < 2.17.0 and 3.0.0.M1-3.6.1 - Deserialization of Untrusted Data in SessionStoreImpl
CVSS 8.8
CVE-2025-31103
HIGH
a-blog cms < 2.8.80 - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.5
CVE-2025-22526
CRITICAL
PHP/MySQL CPU performance statistics <1.2.1 - Object Injection
CVSS 9.8
CVE-2025-2485
HIGH
Contact Form 7 <1.3.8.7 - Code Injection
CVSS 7.5
CVE-2025-26873
CRITICAL
Shine theme Traveler <3.2.1 - Use After Free
CVSS 9.0
CVE-2025-2855
MEDIUM
eladmin < 2.7 - Deserialization of Untrusted Data via /api/deploy/upload checkFile Function
CVSS 4.7
CVE-2025-30773
HIGH
Cozmoslabs TranslatePress <2.9.6 - Object Injection
CVSS 7.2
CVE-2025-2332
CRITICAL
Export All Posts, Products, Orders, Refunds & Users <2.13 - Code In...
CVSS 9.8
CVE-2025-1913
HIGH
Product Import Export for WooCommerce - Code Injection
CVSS 7.2
CVE-2025-29310
CRITICAL
ONOS 2.7.0 - Remote Code Execution via Crafted LLDP Packet Deserialization
CVSS 9.8
CVE-2025-2690
MEDIUM
Yii 2.0.0-2.0.39 - Remote Code Execution via Untrusted Data Deserialization
CVSS 6.3
CVE-2025-2689
MEDIUM
Yii 2.0.0-2.0.45 - Deserialization of Untrusted Data in SortableIterator
CVSS 6.3
Details
Vulnerabilities
2,816
Exploit Likelihood
Medium