CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,987 vulnerabilities with CWE-502
CVE-2026-24250
HIGH
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-24247
HIGH
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-24245
HIGH
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-24244
HIGH
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-24243
HIGH
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-24240
HIGH
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-10538
HIGH
BMC Control-M/Enterprise Manager - Improper Deserialization Handling in Control-M Components
CVSS 8.0
CVE-2026-56700
CRITICAL
Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection
CVSS 9.8
CVE-2026-55223
MEDIUM
c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties
CVE-2026-7871
CRITICAL
IBM Langflow OSS - Insecure Deserialization in Redis Cache Backend
CVSS 9.8
CVE-2026-13759
HIGH
IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
CVSS 7.5
CVE-2026-12578
HIGH
DTMSoft - Deserialization of Untrusted Data Vulnerability
CVE-2026-12240
HIGH
Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
CVSS 8.0
CVE-2026-46386
CRITICAL
OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
CVSS 9.9
CVE-2026-57527
HIGH
ZAP ViewState Add-on Insecure Deserialization via JSFViewState.decode()
CVSS 8.8
CVE-2026-56057
CRITICAL
WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-56055
HIGH
WordPress RealHomes theme <= 4.5.3 - PHP Object Injection vulnerability
CVSS 8.8
CVE-2026-56032
CRITICAL
WordPress Buddyboss Platform plugin <= 3.0.4 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-56031
HIGH
WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-53914
MEDIUM
Jetbrains Kotlin < 2.4.20 - Deserialization of Untrusted Data
CVSS 6.7
CVE-2026-46607
HIGH
Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution
CVSS 7.8
CVE-2026-56053
HIGH
WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability
CVSS 8.8
CVE-2026-10043
HIGH
MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-56121
CRITICAL
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
CVSS 9.8
CVE-2026-54512
HIGH
Jackson Databind - PolymorphicTypeValidator Bypass via Generic Type Parameters
CVSS 8.1
Details
Vulnerabilities
2,987
Exploit Likelihood
Medium