CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,741 vulnerabilities with CWE-502
CVE-2026-33454
CRITICAL
Apache Camel MailHeaderFilterStrategy - MIME Header Injection RCE
CVSS 9.4
CVE-2026-41635
CRITICAL
Apache MINA IoBuffer - Deserialization Remote Code Execution
CVSS 9.8
CVE-2026-40860
CRITICAL
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
CVSS 9.8
CVE-2026-40473
HIGH
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
CVSS 8.8
CVE-2026-40048
HIGH
Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
CVSS 7.8
CVE-2026-33819
CRITICAL
Microsoft Bing Remote Code Execution Vulnerability
CVSS 10.0
CVE-2026-26210
CRITICAL
KTransformers Unsafe Deserialization RCE via balance_serve
CVSS 9.8
CVE-2026-25874
CRITICAL
LeRobot Unsafe Deserialization Remote Code Execution via gRPC
CVSS 9.8
CVE-2026-6857
HIGH
Camel-infinispan: camel-infinispan: remote code execution via unsafe deserialization
CVSS 7.5
CVE-2026-6023
HIGH
Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 8.1
CVE-2026-22016
HIGH
Oracle Java SE and GraalVM - Unauthorized Data Access
CVSS 7.5
CVE-2026-39467
HIGH
WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - PHP Object Injection vulnerability
CVSS 7.2
CVE-2026-25524
HIGH
OpenMage LTS's Phar Deserialization leads to Remote Code Execution
CVSS 8.1
CVE-2026-25917
HIGH
Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)
CVSS 7.2
CVE-2026-33337
HIGH
Firebird Slice Packet Parsing - Buffer Overflow
CVSS 7.5
CVE-2026-40901
HIGH
DataEase: Quartz Deserialization → Remote Code Execution
CVSS 8.8
CVE-2026-5426
CRITICAL
KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value
CVSS 9.1
CVE-2026-34615
CRITICAL
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
CVSS 9.3
CVE-2026-32192
HIGH
Azure Monitor Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-32184
HIGH
Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-27303
CRITICAL
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
CVSS 9.6
CVE-2026-3017
HIGH
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection
CVSS 7.2
CVE-2026-40044
CRITICAL
Pachno 1.0.6 FileCache Deserialization Remote Code Execution
CVSS 9.8
CVE-2026-33858
HIGH
Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
CVSS 8.8
CVE-2026-1462
HIGH
Safe Mode Bypass in keras-team/keras
CVSS 8.8
Details
Vulnerabilities
2,741
Exploit Likelihood
Medium