VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

405 CVEsRSS

CVE-2026-65179High· 8.8
5d ago

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execut…

▾ TwilightNVIDIA · NeMo SpeechEPSS 0.67%via NVD
CVE-2026-65178High· 7.8
5d ago

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denia…

▾ TwilightNVIDIA · NeMo SpeechEPSS 0.38%via NVD
CVE-2026-93088Critical· 9.8PoC
5d ago

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …

▾ AbyssalSGLang · SGLangEPSS 0.73%via NVD
CVE-2026-91827High· 7.5
5d ago

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injec…

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injec…

▾ TwilightEPSS 0.30%via NVD
CVE-2026-19658Critical· 9.8PoC
5d ago

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object…

▾ AbyssalLiquidWeb · Give TributesEPSS 0.53%via NVD
CVE-2026-36471Medium· 5.8
6d ago

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded s…

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded s…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-94301Critical· 9.8
6d ago

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

▾ MidnightApache Software Foundation · Apache MINAEPSS 0.39%via NVD
CVE-2026-94093Medium· 6.3PoC
1w ago

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possi…

▾ TwilightDLR-RM · stable-baselines3EPSS 0.45%via NVD
CVE-2026-94092Medium· 5.5PoC
1w ago

A vulnerability was detected in dmlc dgl up to 2.1.0

A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remot…

▾ Twilightdmlc · dglEPSS 0.34%via NVD
CVE-2026-94091Medium· 5.5PoC
1w ago

A weakness has been identified in piskvorky gensim up to 4.4.0

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is po…

▾ Twilightpiskvorky · gensimEPSS 0.34%via NVD
CVE-2026-85017High· 7.5
1w ago

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers wi…

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers wi…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-93872High· 7.5
1w ago

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potent…

▾ TwilightCotonti · CotontiEPSS 0.71%via NVD
CVE-2026-11711Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.38%via NVD
CVE-2026-81657Critical· 9.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.85%via NVD
CVE-2025-66455Critical· 9.8
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

▾ MidnightInternLM · lmdeployEPSS 0.69%via NVD
CVE-2026-10751High· 7.5
1w ago

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

▾ TwilightIBM · MQEPSS 0.37%via NVD
CVE-2026-17086High· 8.8
1w ago

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible …

▾ Twilightshortpixel · ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIFEPSS 0.89%via NVD
CVE-2026-93467Critical· 9.8
1w ago

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

▾ MidnightHGiga · OAKlouds-custom_page-2.0EPSS 0.91%via NVD
CVE-2026-54752Critical· 9.6PoC
1w ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…

▾ Abyssalnetbox-community · devicetype-libraryEPSS 0.66%via NVD
CVE-2026-76834High· 8.1
1w ago

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated…

▾ Twilightb2evolution · b2evolution CMSEPSS 0.85%via NVD
CVE-2026-92785High· 8.1PoC
1w ago

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending…

▾ MidnightAngel-ML · angelEPSS 0.61%via NVD
CVE-2026-62997High· 7.7
1w ago

Kedro-Datasets provides data connectors for Kedro

Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-s…

▾ Twilightkedro-org · kedro-pluginsEPSS 0.69%via NVD
CVE-2026-20341Critical· 9.1
1w ago

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of u…

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of u…

▾ MidnightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.45%via NVD
CVE-2026-20340High· 8.8
1w ago

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-c…

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-c…

▾ TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.69%via NVD
CVE-2026-20242Critical· 9.8
1w ago

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This v…

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This v…

▾ MidnightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.64%via NVD
CVE-2026-20307Critical· 9.9
1w ago

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the a…

▾ MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.95%via NVD
CVE-2026-20211Critical· 9.1
1w ago

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privilege…

▾ MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.56%via NVD
CVE-2026-70416Critical· 10.0
1w ago

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

▾ Midnightdell · objectscaleEPSS 0.85%via NVD
CVE-2025-59953Critical· 9.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

▾ AbyssalInternLM · lmdeployEPSS 0.80%via NVD
CVE-2026-91939Critical· 9.8PoC
1w ago

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can ex…

▾ AbyssalCotonti · CotontiEPSS 0.98%via NVD
CWE-502 vulnerabilities (CVEs) — page 2 · VulnSea