CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,741 vulnerabilities with CWE-502
CVE-2026-44501
MEDIUM
DataHub OIDC REDIRECT_URL Cookie Deserialization Vulnerability
CVSS 4.3
CVE-2026-1184
MEDIUM
Deserialization of Untrusted Data in GitLab
CVSS 6.5
CVE-2026-41957
HIGH
F5 - BIG-IP and BIG-IQ Configuration Utility Vulnerability
CVSS 8.8
CVE-2026-7635
HIGH
coreActivity: Activity Logging for WordPress <= 3.0 - Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field
CVSS 8.1
CVE-2026-34659
CRITICAL
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
CVSS 9.6
CVE-2026-40368
HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-40357
HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-35439
HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-33112
HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-33110
HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-31239
CRITICAL
mamba < 2.2.6 - Remote Code Execution via Insecure Model Deserialization
CVSS 9.8
CVE-2026-31238
CRITICAL
Ludwig Framework <=0.10.4 - Deserialization
CVSS 9.8
CVE-2026-31237
CRITICAL
Ludwig Framework <=0.10.4 - Deserialization
CVSS 9.8
CVE-2026-31235
CRITICAL
imgaug <= 0.4.0 - Remote Code Execution via Insecure Pickle Deserialization in BackgroundAugmenter
CVSS 9.8
CVE-2026-31234
CRITICAL
Horovod <= 0.28.1 - Unauthenticated Remote Code Execution via Insecure KVStore Deserialization
CVSS 9.8
CVE-2026-31232
HIGH
CosyVoice thru 6e01309 - Deserialization
CVSS 8.8
CVE-2026-31229
CRITICAL
Adversarial Robustness Toolbox <=1.20.1 - Deserialization
CVSS 9.8
CVE-2026-31224
HIGH
snorkel < 0.10.0 - Remote Code Execution via Insecure Pickle Deserialization in MultitaskClassifier.load()
CVSS 8.8
CVE-2026-31223
HIGH
snorkel < 0.10.0 - Remote Code Execution via Insecure Pickle Deserialization in BaseLabeler.load()
CVSS 8.8
CVE-2026-31222
HIGH
snorkel thru v0.10.0 - Deserialization
CVSS 8.8
CVE-2026-31221
HIGH
PyTorch-Lightning <=2.6.0 - Deserialization
CVSS 7.8
CVE-2026-31219
HIGH
optimate - Remote Code Execution via Insecure Model File Deserialization
CVSS 8.8
CVE-2026-31218
HIGH
nebuly-ai optimate - Remote Code Execution via Insecure Pickle Deserialization in _load_model()
CVSS 8.8
CVE-2026-31214
CRITICAL
ml-engineering 0099885 - Deserialization
CVSS 9.8
CVE-2026-3048
MEDIUM
Nexus Repository 3 - Improper LDAP Referral Handling
Details
Vulnerabilities
2,741
Exploit Likelihood
Medium