VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

405 CVEsRSS

CVE-2026-12728High· 8.8
1w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

▾ TwilightIBM · MQEPSS 0.39%via NVD
CVE-2026-11729High· 8.5
1w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

▾ TwilightIBM · MQEPSS 0.31%via NVD
CVE-2023-54398Critical· 9.8PoC
1w ago

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

▾ AbyssalYonyou · U8 CloudEPSS 0.64%via NVD
CVE-2026-91842Medium· 4.1PoC
1w ago

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads t…

▾ TwilightOpenBankProject · OBP-APIEPSS 0.38%via NVD
CVE-2026-62263Critical· 9.2
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only …

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.86%via NVD
CVE-2026-46495Critical· 9.2
1w ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authen…

▾ MidnightOpenIdentityPlatform · OpenDJEPSS 1.1%via NVD
CVE-2026-45051Critical· 9.2
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInp…

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.69%via NVD
CVE-2026-45794High· 7.7
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.63%via NVD
CVE-2026-67399Critical· 9.3
1w ago

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

▾ MidnightWebPros · WHMCSEPSS 0.75%via NVD
CVE-2026-13293High· 8.8
1w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attack…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attack…

▾ TwilightIBM · MQEPSS 0.65%via NVD
CVE-2026-17416High· 7.8
1w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.14%via NVD
CVE-2026-17156High· 7.8
1w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.14%via NVD
CVE-2026-61701High· 8.8
1w ago

Laravel MagicLink creates links for authentication without a password or for accessing private content

Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them t…

▾ Twilightcesargb · laravel-magiclinkEPSS 0.76%via NVD
CVE-2026-49400Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserial…

▾ Sunlitoctobercms · octoberEPSS 0.24%via NVD
CVE-2026-90614Medium· 6.3
1w ago

A weakness has been identified in FedML-AI FedML up to 0.9.6

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backen…

▾ SunlitFedML-AI · FedMLEPSS 0.43%via NVD
CVE-2026-90919Critical· 9.8PoC
1w ago

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads()

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Confi…

▾ AbyssalModelTC · LightLLMEPSS 1.1%via NVD
CVE-2026-90490Medium· 6.3PoC
2w ago

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remot…

▾ Twilightlenve · vhrEPSS 0.41%via NVD
CVE-2026-90777High· 8.8PoC
2w ago

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code dur…

▾ Midnightespnet · espnetEPSS 0.73%via NVD
CVE-2026-90575Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Small CRM 4.0

A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. I…

▾ TwilightPHPGurukul · Small CRMEPSS 0.48%via NVD
CVE-2026-78175High· 8.8
2w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…

▾ Twilightthemeum · Tutor LMS – eLearning and online course solutionEPSS 1.1%via NVD
CVE-2026-78006Critical· 9.8PoC
2w ago

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance,…

▾ Abyssalstellarwp · The Events CalendarEPSS 1.5%via NVD
CVE-2026-84099High· 8.1
2w ago

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inj…

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inj…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-82845Critical· 9.9
2w ago

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of…

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of…

▾ MidnightEPSS 0.64%via NVD
CVE-2026-87719Critical· 9.9
2w ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated u…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated u…

▾ MidnightGitLab · GitLabEPSS 0.57%via NVD
CVE-2026-62105Critical· 9.8
2w ago

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

▾ MidnightThemeRex · ThemeREX AddonsEPSS 0.56%via NVD
CVE-2026-62107High· 8.8
2w ago

WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

▾ Twilightmasteriyo · learning-management-systemEPSS 0.52%via CVEORG
CVE-2026-62103Critical· 9.8
2w ago

WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

▾ Midnightwpeverest · everest-formsEPSS 0.56%via CVEORG
CVE-2026-81784High· 8.1
2w ago

WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.

▾ TwilightMarcin · wise-chatEPSS 0.44%via CVEORG
CVE-2026-57822Medium· 6.5
2w ago

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

▾ Sunlitapache · artemisEPSS 0.70%via NVD
CVE-2026-73699High· 7.2PoC
2w ago

FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a position…

▾ MidnightFileRun · FileRunEPSS 0.78%via CVEORG
CWE-502 vulnerabilities (CVEs) — page 3 · VulnSea