CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,816 vulnerabilities with CWE-502
CVE-2025-0767 CRITICAL
WP Activity Log <5.3.2 - Code Injection
CVSS 9.8
CVE-2025-1741 MEDIUM
b1gMail <7.4.1-pl1 - Deserialization
CVSS 4.7
CVE-2025-26900 CRITICAL
Flexmls IDX <3.14.27 - Object Injection
CVSS 9.8
CVE-2025-27301 HIGH
NHR Options Table Manager <1.1.2 - Code Injection
CVSS 7.2
CVE-2025-27300 HIGH
giuliopanda ADFO <1.9.1 - Object Injection
CVSS 7.2
CVE-2025-26763 CRITICAL
MetaSlider Responsive Slider <3.94.0 - Code Injection
CVSS 9.8
CVE-2025-1556 MEDIUM
westboy CicadasCMS 1.0 - Deserialization of Untrusted Data in Template Management
CVSS 4.7
CVE-2025-1403 HIGH
Qiskit 0.45.0-1.2.4 - Denial of Service via Malformed Symengine Serialization Stream
CVSS 8.6
CVE-2025-1186 MEDIUM
xunruicms < 4.6.4 - Deserialization of Untrusted Data via Thumb Argument
CVSS 6.3
CVE-2025-1177 MEDIUM
XunRuiCMS 4.6.3 - Deserialization of Untrusted Data in Linkage Import Function
CVSS 6.3
CVE-2025-24016 CRITICAL KEV
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.
CVSS 9.9
CVE-2025-1113 MEDIUM
taisan tarzan-cms <= 1.0.0 - Deserialization of Untrusted Data via Add Theme Handler
CVSS 6.3
CVE-2025-1077 CRITICAL
IBL Software Engineering Visual Weather - RCE
CVE-2025-0994 HIGH KEV
Trimble Cityworks < 15.8.9 - Authenticated Remote Code Execution via Deserialization
CVSS 8.8
CVE-2025-20124 CRITICAL
Cisco Identity Services Engine - Authenticated Remote Code Execution via Insecure Java Deserialization
CVSS 9.9
CVE-2025-24661 HIGH
MagePeople Team Taxi Booking Manager for WooCommerce <1.1.8 - Code ...
CVSS 8.8
CVE-2025-0974 MEDIUM
MaxD Lightning Module 4.43 - Deserialization
CVSS 5.0
CVE-2025-24794 MEDIUM
Snowflake Connector for Python 2.7.12-3.13.0 - Local Privilege Escalation via OCSP Response Cache Deserialization
CVSS 6.7
CVE-2025-0841 HIGH
Aridius XYZ <20240927 - Deserialization
CVSS 7.3
CVE-2025-23045 CRITICAL
CVAT 1.1.0-2.25.9 - Authenticated Remote Code Execution via Unsafe State Deserialization in Tracker Functions
CVSS 9.8
CVE-2025-0734 MEDIUM
y_project RuoYi <4.8.0 - Deserialization
CVSS 4.7
CVE-2025-24357 HIGH
vllm < 0.7.0 - Remote Code Execution via Pickle Deserialization in Model Weight Loading
CVSS 7.5
CVE-2025-24671 CRITICAL
Pdfcrowd Save as PDF <4.4.0 - Code Injection
CVSS 9.8
CVE-2025-24601 CRITICAL
ThimPress FundPress <2.0.6 - Code Injection
CVSS 9.8
CVE-2025-23006 CRITICAL KEV
SonicWall SMA/SRA < 12.4.3 - Unauthenticated RCE via Deserialization
CVSS 9.8
Details
Vulnerabilities 2,816
Exploit Likelihood Medium