CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,594 vulnerabilities with CWE-502
CVE-2026-27206 HIGH
Zumba Json Serializer <=3.2.2 - Deserialization
CVSS 8.1
CVE-2026-2037 HIGH
GFI Archiver - Deserialization RCE
CVSS 8.8
CVE-2026-2036 HIGH
GFI Archiver - Deserialization RCE
CVSS 8.8
CVE-2026-24892 HIGH
openITCOCKPIT <=5.3.1 - Deserialization
CVSS 7.5
CVE-2026-24891 HIGH
openITCOCKPIT <=5.3.1 - Deserialization
CVSS 7.5
CVE-2026-22384 CRITICAL
Applay - Shortcodes <=3.7 - Deserialization
CVSS 9.8
CVE-2026-22354 HIGH
Woocommerce Category Banner Management <=2.5.1 - Deserialization
CVSS 8.8
CVE-2026-22346 HIGH
Slider Responsive Slideshow <=1.5.4 - Deserialization
CVSS 8.8
CVE-2026-22345 HIGH
A WP Life Image Gallery <=1.6.0 - Deserialization
CVSS 8.8
CVE-2026-27475 HIGH
SPIP <4.4.9 - Deserialization
CVSS 8.1
CVE-2026-25316 HIGH
CartFlows <=2.1.19 - Deserialization
CVSS 7.2
CVE-2026-23549 CRITICAL
WpEvently <=5.1.1 - Deserialization
CVSS 9.8
CVE-2026-23544 HIGH
Valenti <=5.6.3.5 - Deserialization
CVSS 8.8
CVE-2026-23542 CRITICAL
ThemeGoods Grand Restaurant <=7.0.10 - Deserialization
CVSS 9.8
CVE-2026-22333 HIGH
YITH WooCommerce Compare <=3.6.0 - Deserialization
CVSS 7.2
CVE-2026-1426 HIGH
Advanced AJAX Product Filters <=3.1.9.6 - Deserialization
CVSS 8.8
CVE-2026-26220 CRITICAL
LightLLM <=1.1.0 - Unauthenticated RCE
CVE-2026-2555 MEDIUM
JeecgBoot 3.9.1 - Deserialization
CVSS 5.0
CVE-2026-26333 CRITICAL
Calero VeraSMART <2022 R1 - Unauthenticated Code Injection
CVSS 9.8
CVE-2026-26208 HIGH
ADB Explorer <Beta 0.9.26020 - RCE
CVSS 7.8
CVE-2026-26221 CRITICAL
Hyland OnBase - Unauthenticated RCE
CVSS 9.8
CVE-2026-26215 CRITICAL
manga-image-translator <beta-0.3 - Unauthenticated RCE
CVE-2026-0910 HIGH
wpForo Forum <2.4.13 - Code Injection
CVSS 8.8
CVE-2026-1235 MEDIUM
WP eCommerce <3.15.1 - Code Injection
CVSS 6.5
CVE-2026-21531 CRITICAL
Microsoft Azure Conversation Authorin... - Insecure Deserialization
CVSS 9.8
Details
Vulnerabilities 2,594
Exploit Likelihood Medium