VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

330 CVEsRSS

CVE-2026-94301Critical· 9.8
today

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

MidnightApache Software Foundation · Apache MINAvia NVD
CVE-2026-94093Medium· 6.3PoC
yesterday

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possi…

TwilightDLR-RM · stable-baselines3EPSS 0.26%via NVD
CVE-2026-94092Medium· 5.5
yesterday

A vulnerability was detected in dmlc dgl up to 2.1.0

A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remot…

Sunlitdmlc · dglEPSS 0.19%via NVD
CVE-2026-94091Medium· 5.5PoC
yesterday

A weakness has been identified in piskvorky gensim up to 4.4.0

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is po…

Twilightpiskvorky · gensimEPSS 0.19%via NVD
CVE-2026-85017High· 7.5
yesterday

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers wi…

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers wi…

TwilightEPSS 0.24%via NVD
CVE-2026-93872High· 7.5
3d ago

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potent…

TwilightCotonti · CotontiEPSS 0.44%via NVD
CVE-2026-11711Medium· 6.5
3d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

SunlitIBM · WebSphere Application ServerEPSS 0.38%via NVD
CVE-2026-81657Critical· 9.8
3d ago

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

MidnightIBM · Guardium Data ProtectionEPSS 0.58%via NVD
CVE-2025-66455Critical· 9.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

MidnightInternLM · lmdeployEPSS 0.70%via NVD
CVE-2026-10751High· 7.5
3d ago

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

TwilightIBM · MQEPSS 0.51%via NVD
CVE-2026-17086High· 8.8
3d ago

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible …

Twilightshortpixel · ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIFEPSS 0.89%via NVD
CVE-2026-93467Critical· 9.8
3d ago

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

MidnightHGiga · OAKlouds-custom_page-2.0EPSS 0.52%via NVD
CVE-2026-54752Critical· 9.6
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…

Midnightnetbox-community · devicetype-libraryEPSS 0.35%via NVD
CVE-2026-76834High· 8.1
4d ago

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated…

Twilightb2evolution · b2evolution CMSEPSS 0.85%via NVD
CVE-2026-92785High· 8.1PoC
5d ago

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending…

MidnightAngel-ML · angelEPSS 0.36%via NVD
CVE-2026-62997High· 7.7
5d ago

Kedro-Datasets provides data connectors for Kedro

Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-s…

Twilightkedro-org · kedro-pluginsEPSS 0.39%via NVD
CVE-2026-20341Critical· 9.1
5d ago

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of u…

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of u…

MidnightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.45%via NVD
CVE-2026-20340High· 8.8
5d ago

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-c…

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-c…

TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.69%via NVD
CVE-2026-20242Critical· 9.8
5d ago

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This v…

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This v…

MidnightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.64%via NVD
CVE-2026-20307Critical· 9.9
5d ago

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the a…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.95%via NVD
CVE-2026-20211Critical· 9.1
5d ago

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privilege…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.56%via NVD
CVE-2026-70416Critical· 10.0
5d ago

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Midnightdell · objectscaleEPSS 0.91%via NVD
CVE-2025-59953Critical· 9.8PoC
5d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

AbyssalInternLM · lmdeployEPSS 0.68%via NVD
CVE-2026-91939Critical· 9.8PoC
6d ago

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can ex…

AbyssalCotonti · CotontiEPSS 0.59%via NVD
CVE-2026-12728High· 8.8
6d ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

TwilightIBM · MQEPSS 0.64%via NVD
CVE-2026-11729High· 8.5
6d ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

TwilightIBM · MQEPSS 0.29%via NVD
CVE-2023-54398Critical· 9.8PoC
6d ago

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

AbyssalYonyou · U8 CloudEPSS 0.64%via NVD
CVE-2026-91842Medium· 4.1PoC
6d ago

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads t…

TwilightOpenBankProject · OBP-APIEPSS 0.37%via NVD
CVE-2026-62263Critical· 9.2
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only …

MidnightOpenIdentityPlatform · OpenAMEPSS 0.55%via NVD
CVE-2026-46495Critical· 9.2
6d ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authen…

MidnightOpenIdentityPlatform · OpenDJEPSS 0.73%via NVD
CWE-502 vulnerabilities (CVEs) · VulnSea