VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

404 CVEsRSS

CVE-2025-55182Critical· 10.0CISA KEVPoC
9mo ago

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

▾ Hadalfacebook · reactEPSS 100%via NVD
CVE-2025-13805Low· 3.7
10mo ago

A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT

A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoin…

▾ SunlitEPSS 0.37%via NVD
CVE-2025-61168Critical· 9.8
10mo ago

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

▾ Midnightsigb · pmbEPSS 0.49%via NVD
CVE-2025-34292None
11mo ago

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in …

▾ SunlitEPSS 0.55%via NVD
CVE-2025-60828Medium· 6.5
11mo ago

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

▾ Sunlit5kcrm · wukong_crmEPSS 0.36%via NVD
CVE-2025-48459Medium· 5.3
1y ago

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.

▾ Sunlitapache · iotdbEPSS 0.49%via NVD
CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

▾ Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2025-54742High· 8.8
1y ago

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.4.8.

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.4.8.

▾ TwilightEPSS 0.37%via NVD
CVE-2025-53584High· 8.1
1y ago

Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Object Injection.This issue affects WP Ticket Customer Service Software & Support Ticket Syste…

Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Object Injection.This issue affects WP Ticket Customer Service Software & Support Ticket Syste…

▾ TwilightEPSS 0.33%via NVD
CVE-2025-53583High· 8.1
1y ago

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object Injection.This issue affects Employee Spotlight: from n/a through <= 5.1.1.

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object Injection.This issue affects Employee Spotlight: from n/a through <= 5.1.1.

▾ TwilightEPSS 0.33%via NVD
CVE-2025-53572High· 8.1
1y ago

Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injection.This issue affects WP Easy Contact: from n/a through <= 4.0.1.

Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injection.This issue affects WP Easy Contact: from n/a through <= 4.0.1.

▾ TwilightEPSS 0.33%via NVD
CVE-2024-13980None
1y ago

H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint

H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to cra…

▾ SunlitEPSS 0.96%via NVD
CVE-2025-71378Medium
1y ago

Picklescan is missing detection when calling built-in Python cProfile.runctx

Picklescan is missing detection when calling built-in Python cProfile.runctx

▾ Sunlitpicklescan · picklescanEPSS 0.48%via OSV
CVE-2025-71357High
1y ago

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

▾ Twilightpicklescan · picklescanEPSS 0.39%via OSV
CVE-2025-71376High· 8.1
1y ago

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

▾ Twilightpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-71341High· 8.1
1y ago

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

▾ Twilightpicklescan · picklescanEPSS 0.61%via OSV
CVE-2025-71370High· 8.1
1y ago

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

▾ Twilightpicklescan · picklescanEPSS 0.54%via OSV
CVE-2025-8875High· 7.8CISA KEV0dayPoC
1y ago

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

▾ Abyssaln-able · n-centralEPSS 1.9%via NVD
CVE-2016-15044NonePoC
1y ago

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by send…

▾ TwilightEPSS 2.1%via NVD
CVE-2025-53770Critical· 9.8CISA KEV0dayPoC
1y ago

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

▾ Hadalmicrosoft · sharepoint_serverEPSS 100%via NVD
CVE-2025-42999Critical· 9.1CISA KEV
1y ago

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…

▾ Hadalsap · netweaverEPSS 14%via NVD
CVE-2025-2251Medium· 6.2
1y ago

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshallin…

▾ SunlitEPSS 1.0%via NVD
CVE-2025-23006Critical· 9.8CISA KEV0day
1y ago

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

▾ Hadalsonicwall · sma8200vEPSS 23%via NVD
CVE-2024-35249High· 8.8
2y ago

Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

▾ Twilightmicrosoft · dynamics_365_business_centralEPSS 3.4%via NVD
CVE-2024-23052Critical· 9.8
2y ago

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

▾ Midnight5kcrm · wukong_crmEPSS 4.9%via NVD
CVE-2023-0669High· 7.2CISA KEVPoC
3y ago

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…

▾ Abyssalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2021-36665High· 7.8
4y ago

An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

▾ Twilightdruva · insync_clientEPSS 0.51%via NVD
CVE-2022-29528Critical· 9.8
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

▾ Midnightmisp-project · mispEPSS 2.2%via NVD
CVE-2021-42631High· 8.1
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

▾ Twilightprinterlogic · virtual_applianceEPSS 6.2%via NVD
CVE-2021-23758High· 8.1CISA KEVPoC
4y ago

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

▾ Abyssalajaxpro.2_project · ajaxpro.2EPSS 83%via NVD
CWE-502 vulnerabilities (CVEs) — page 12 · VulnSea