CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,816 vulnerabilities with CWE-502
CVE-2025-2622 MEDIUM
aizuda snail-job 1.4.0 - Deserialization
CVSS 6.3
CVE-2025-1971 HIGH
Export and Import Users and Customers <= 2.6.2 - Authenticated PHP Object Injection via Form Data Parameter
CVSS 7.2
CVE-2025-0724 HIGH
ProfileGrid - WordPress <5.9.4.5 - Code Injection
CVSS 8.8
CVE-2025-29807 HIGH
Microsoft Dataverse - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.7
CVE-2025-30160 HIGH
redlib < 0.36.0 - Denial of Service via Base2048-Encoded DEFLATE Decompression Bomb
CVSS 7.5
CVE-2025-23120 HIGH
Veeam Backup & Replication 12.0.0.1402-12.3.1.1139 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2025-27781 CRITICAL
Applio < 3.2.8-bugfix - Remote Code Execution via Unsafe Deserialization in Model File Handling
CVSS 9.8
CVE-2025-27780 CRITICAL
Applio < 3.2.8-bugfix - Remote Code Execution via Unsafe Deserialization in model_information.py
CVSS 9.8
CVE-2025-27779 CRITICAL
Applio < 3.2.8-bugfix - Remote Code Execution via Unsafe Deserialization in model_blender.py
CVSS 9.8
CVE-2025-27778 CRITICAL
Applio < 3.2.8-bugfix - Remote Code Execution via Unsafe Deserialization in infer.py
CVSS 9.8
CVE-2025-29783 CRITICAL
vllm 0.6.5-0.7.9 - Remote Code Execution via Unsafe Mooncake Deserialization
CVSS 9.0
CVE-2025-2376 HIGH
viames Pair Framework <1.9.11 - Deserialization
CVSS 7.3
CVE-2025-26921 HIGH
Booking and Rental Manager <2.2.6 - Object Injection
CVSS 8.8
CVE-2025-2000 CRITICAL
Qiskit 0.18.0-1.4.1 - Remote Code Execution via QPY Deserialization
CVSS 9.8
CVE-2025-27925 HIGH
Nintex Automation 5.6-5.7 - Deserialization of Untrusted Data
CVSS 8.5
CVE-2025-24813 CRITICAL KEV
Tomcat Partial PUT Java Deserialization
CVSS 9.8
CVE-2025-25940 CRITICAL
VisiCut 2.1 - Remote Code Execution via Insecure XML Deserialization in loadPlfFile
CVSS 9.8
CVE-2025-27816 CRITICAL
Arctera InfoScale 7.0-8.0.2 - Open Redirect
CVSS 9.8
CVE-2025-2043 MEDIUM
pb-cms 1.0.0 - Deserialization of Untrusted Data via Topic Key
CVSS 4.7
CVE-2025-0956 HIGH
WooCommerce Recover Abandoned Cart <24.3.0 - Code Injection
CVSS 8.1
CVE-2025-0912 CRITICAL
GiveWP < 3.20.0 - Unauthenticated PHP Object Injection via Donation Form card_address Parameter
CVSS 9.8
CVE-2025-26999 HIGH
Metagauss ProfileGrid <5.9.4.3 - Code Injection
CVSS 8.8
CVE-2025-26967 HIGH
Events Calendar for GeoDirectory <= 2.3.14 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.8
CVE-2025-26885 HIGH
Brent Jett Assistant <1.5.1 - Object Injection
CVSS 7.2
CVE-2025-0769 MEDIUM
PixelYourSite 10.1.1.1 - Deserialization of Untrusted Data in Facebook Server Async Task
Details
Vulnerabilities 2,816
Exploit Likelihood Medium