VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

405 CVEsRSS

CVE-2026-1462High· 7.8
5mo ago

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…

▾ Twilightkeras · kerasEPSS 0.40%via NVD
CVE-2026-3199High· 8.8
5mo ago

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCrea…

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCrea…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.77%via NVD
CVE-2026-23869High· 7.5PoC
5mo ago

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

▾ MidnightEPSS 1.6%via NVD
CVE-2026-3296Critical· 9.8PoC
5mo ago

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php…

▾ AbyssalEPSS 3.0%via NVD
CVE-2026-3357High· 8.8
5mo ago

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

▾ Twilightlangflow · langflowEPSS 0.65%via NVD
CVE-2026-32590High· 7.1
5mo ago

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code …

▾ Twilightredhat · mirror_registry_for_red_hat_openshiftEPSS 0.79%via NVD
CVE-2026-33439Critical· 9.8PoC
5mo ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…

▾ Abyssalopenidentityplatform · openamEPSS 8.4%via NVD
CVE-2026-24156High· 7.3
5mo ago

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

▾ Twilightnvidia · data_loading_libraryEPSS 0.26%via NVD
CVE-2026-34202High· 7.5
6mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic…

▾ Twilightzfnd · zebraEPSS 0.93%via NVD
CVE-2026-24165High· 7.8
6mo ago

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

▾ Twilightnvidia · bionemo_frameworkEPSS 0.31%via NVD
CVE-2026-24164High· 8.8
6mo ago

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

▾ Twilightnvidia · bionemo_frameworkEPSS 0.47%via NVD
CVE-2026-4266Medium· 6.7
6mo ago

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. No…

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. No…

▾ Sunlitwatchguard · firewareEPSS 0.39%via NVD
CVE-2026-33701Critical· 9.8PoC
6mo ago

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data with…

▾ Abyssallinuxfoundation · opentelemetry_instrumentation_for_javaEPSS 1.1%via NVD
CVE-2025-71260High· 8.8
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can…

▾ Twilightbmc · footprintsEPSS 34%via NVD
CVE-2026-1286Medium· 6.5
6mo ago

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.

▾ SunlitEPSS 0.32%via NVD
CVE-2025-11739High· 7.8
6mo ago

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

▾ TwilightEPSS 0.19%via NVD
CVE-2026-27830High· 8.0
7mo ago

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `user…

▾ Twilightswaldman · c3p0EPSS 2.1%via NVD
CVE-2026-27727Critical· 9.8PoC
7mo ago

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

▾ Abyssalmchange · mchange_commons_javaEPSS 1.6%via NVD
CVE-2026-25747High· 8.8PoC
7mo ago

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

▾ Midnightapache · camelEPSS 0.89%via NVD
CVE-2025-69872Critical· 9.8
7mo ago

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

▾ Midnightdiskcache · diskcacheEPSS 0.53%via NVD
CVE-2025-61140Critical· 9.8
8mo ago

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

▾ Midnightdchester · jsonpathEPSS 0.51%via NVD
CVE-2026-24747High· 8.8
8mo ago

PyTorch is a Python package that provides tensor computation

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.l…

▾ Twilightlinuxfoundation · pytorchEPSS 0.81%via NVD
CVE-2026-23864High· 7.5
8mo ago

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

▾ Twilightfacebook · reactEPSS 2.6%via NVD
CVE-2025-56005Critical· 9.8PoC⚖ disputed
8mo ago

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pick…

▾ Abyssaldabeaz · plyEPSS 19%via NVD
CVE-2025-11157High· 7.8
8mo ago

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability…

▾ TwilightEPSS 0.30%via NVD
CVE-2025-71365High· 8.1
9mo ago

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

▾ Twilightpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-68664Critical· 9.3PoC
9mo ago

langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)

A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…

▾ AbyssalRed Hat · Red Hat Ansible Automation Platform 2.5EPSS 43%via CSAF
CVE-2025-64233Critical· 9.8
9mo ago

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

▾ MidnightEPSS 0.38%via NVD
CVE-2025-64227Critical· 9.8
9mo ago

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

▾ MidnightEPSS 0.38%via NVD
CVE-2025-9571None
9mo ago

A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component

A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the a…

▾ SunlitEPSS 0.44%via NVD
CWE-502 vulnerabilities (CVEs) — page 11 · VulnSea