CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,594 vulnerabilities with CWE-502
CVE-2026-22475 CRITICAL
axiomthemes Estate <=1.3.4 - Deserialization
CVSS 9.8
CVE-2026-22474 CRITICAL
ThemeREX Equestrian Centre <=1.5 - Deserialization
CVSS 9.8
CVE-2026-22473 HIGH
Dental Clinic <=3.7 - Deserialization
CVSS 8.8
CVE-2026-22471 HIGH
Secudeal Payments for Ecommerce <=1.1 - Deserialization
CVSS 8.8
CVE-2026-22454 CRITICAL
ThemeREX Solaris <=2.5 - Deserialization
CVSS 9.8
CVE-2026-22453 CRITICAL
ThemeREX Pets Club <=2.3 - Deserialization
CVSS 9.8
CVE-2026-22451 CRITICAL
AncoraThemes Handyman <=1.4 - Deserialization
CVSS 9.8
CVE-2026-22417 CRITICAL
ThemeGoods Grand Wedding <=3.1.0 - Deserialization
CVSS 9.8
CVE-2026-20131 CRITICAL KEV
Cisco FMC - Deserialization
CVSS 10.0
CVE-2026-3452 HIGH
Concrete CMS <9.4.8 - RCE
CVSS 7.2
CVE-2026-27971 CRITICAL
Qwik <=1.19.0 - Deserialization RCE
CVSS 9.8
CVE-2026-3422 CRITICAL
U-Office Force - Deserialization
CVSS 9.8
CVE-2026-2471 HIGH
WP Mail Logging <=1.15.0 - Deserialization
CVSS 7.5
CVE-2026-1542 MEDIUM
Super Stage WP WordPress Plugin <1.0.1 - Deserialization
CVSS 6.5
CVE-2026-21619 HIGH
hex_core <0.1.0 - Deserialization
CVSS 7.5
CVE-2026-27776 HIGH
intra-mart Accel Platform IM-LogicDesigner - Deserialization
CVSS 8.8
CVE-2026-3071 HIGH
Flair 0.4.1-latest - Deserialization
CVSS 8.4
CVE-2026-28138 HIGH
uListing <=2.2.0 - Deserialization
CVSS 7.2
CVE-2026-27830 HIGH
c3p0 <0.12.0 - Deserialization
CVE-2026-27794 MEDIUM
LangGraph Checkpoint <4.0.0 - Deserialization
CVSS 6.6
CVE-2026-26222 CRITICAL
Altec DocLink 4.0.336.0 - Deserialization
CVSS 9.8
CVE-2026-21665 HIGH
Fiserv Originate Loans Peripherals 2021.2.4 - Deserialization
CVE-2026-25747 HIGH
Apache Camel LevelDB - Deserialization
CVSS 8.8
CVE-2026-2970 MEDIUM
datapizza-ai 0.0.2 - Deserialization
CVSS 4.6
CVE-2026-2898 MEDIUM
funadmin <7.1.0-rc4 - Deserialization
CVSS 5.5
Details
Vulnerabilities 2,594
Exploit Likelihood Medium