CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,987 vulnerabilities with CWE-502
CVE-2026-41862 HIGH
Spring Statemachine - Deserialization of Untrusted Data
CVSS 8.8
CVE-2026-39253 HIGH
Pivotal CRM 6.6.04.08 - Remote Code Execution via Insecure Deserialization
CVSS 8.1
CVE-2026-48517 HIGH
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
CVSS 7.5
CVE-2026-48502 HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-45034 CRITICAL
PhpSpreadsheet: File::prohibitWrappers bypass
CVE-2026-12787 MEDIUM
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserialization
CVSS 6.3
CVE-2026-56304 MEDIUM
picklescan - Arbitrary File Creation via logging.FileHandler Deserialization
CVSS 6.5
CVE-2026-48909 CRITICAL
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
CVE-2026-49286 HIGH
PhpWeasyPrint < 2.6.0 - PHAR Deserialization via Output Filename
CVSS 8.1
CVE-2026-12046 CRITICAL
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
CVSS 9.0
CVE-2026-8024 CRITICAL
ibaPDA <= 8.14.0 / ibaDatCoordinator <= 4.0.7 - Unauthenticated Deserialization
CVSS 9.8
CVE-2026-12569 CRITICAL KEV
PTC Windchill PDMLink and FlexPLM - Deserialization Remote Code Execution
CVSS 9.8
CVE-2026-53805 CRITICAL
NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API
CVSS 9.8
CVE-2026-53874 CRITICAL
picklescan - Arbitrary Code Execution via Obfuscated eval Call
CVSS 9.8
CVE-2026-49108 CRITICAL
WordPress Moderno theme < 1.43 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-40757 HIGH
WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40756 HIGH
WordPress Zoya theme <= 1.4 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40752 HIGH
WordPress Manufaktur Solutions theme <= 1.1.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40738 HIGH
WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40733 HIGH
WordPress ShiftUp theme <= 1.3 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39576 HIGH
WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39560 HIGH
WordPress Hiroshi theme <= 1.5.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39556 HIGH
WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39445 HIGH
WordPress Alukas theme < 3.0.0 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39442 HIGH
WordPress PressMart theme <= 1.2.26 - PHP Object Injection vulnerability
CVSS 8.1
Details
Vulnerabilities 2,987
Exploit Likelihood Medium