VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

404 CVEsRSS

CVE-2026-82925High· 8.1
2w ago

The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on inst…

The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on inst…

▾ TwilightEPSS 0.45%via NVD
CVE-2024-58381High· 7.5
2w ago

PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data

PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization f…

▾ Twilightpmmp · PocketMine-MPEPSS 0.43%via NVD
CVE-2026-87930High· 8.1PoC
2w ago

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to…

▾ MidnightMaxSite · MaxSite CMSEPSS 0.61%via NVD
CVE-2026-87874High· 8.1
2w ago

A flaw was found in the memcached cache plugin of the community.general Ansible collection

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memc…

▾ TwilightRed Hat · ansible-collection-community-generalEPSS 0.72%via NVD
CVE-2026-11363Medium· 6.6
2w ago

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for au…

▾ Sunlitkstover · Ninja Forms – The Contact Form Builder That Grows With YouEPSS 0.66%via NVD
CVE-2026-87083Medium· 5.5
2w ago

A weakness has been identified in tile-ai tilelang up to 0.1.14

A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to …

▾ Sunlittile-ai · tilelangEPSS 0.34%via NVD
CVE-2026-79721High· 8.6
2w ago

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

▾ Twilightmlflow · mlflowEPSS 0.47%via NVD
CVE-2026-81385High· 8.8
2w ago

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 1.3%via NVD
CVE-2026-77484High· 8.8
2w ago

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2019EPSS 1.7%via NVD
CVE-2026-69694High· 7.0
2w ago

Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.

Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 2.8%via NVD
CVE-2026-65772High· 8.8
2w ago

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Dynamics 365 (on-premises) version 9.1EPSS 1.7%via NVD
CVE-2026-47297High· 8.1
2w ago

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SQL Server 2019 (CU 32)EPSS 1.1%via NVD
CVE-2026-16502High· 8.8
2w ago

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated …

▾ Twilightlivecomposer · Live Composer – Free WordPress Website BuilderEPSS 0.45%via NVD
CVE-2026-12745Critical· 9.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

▾ Midnightivanti · neurons_for_itsmEPSS 2.2%via NVD
CVE-2026-12744Critical· 9.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

▾ Midnightivanti · neurons_for_itsmEPSS 2.3%via NVD
CVE-2026-12651High· 8.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

▾ Twilightivanti · neurons_for_itsmEPSS 1.5%via NVD
CVE-2026-12650Critical· 9.9
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

▾ Midnightivanti · neurons_for_itsmEPSS 1.6%via NVD
CVE-2026-12648High· 8.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

▾ Twilightivanti · neurons_for_itsmEPSS 1.5%via NVD
CVE-2026-77092Critical· 9.8⚖ disputed
2w ago

Content Extractor contained a deserialization of untrusted data issue affecting privilege management

Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.

▾ Midnightcommvault · commvaultEPSS 0.32%via NVD
CVE-2026-71374Critical· 9.8
2w ago

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 thr…

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 thr…

▾ MidnightHitachi · Cosminexus Component ContainerEPSS 0.56%via NVD
CVE-2026-76967High· 7.8
2w ago

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially craft…

▾ TwilightSAP_SE · SAP NetWeaver Business ClientEPSS 0.36%via NVD
CVE-2026-79657Critical
2w ago

NLTK: Allowlisted pickle loaders still permit code execution in current source

NLTK: Allowlisted pickle loaders still permit code execution in current source

▾ Midnightnltk · nltkEPSS 1.3%via OSV
CVE-2026-78683Critical
2w ago

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

▾ Midnightnltk · nltkEPSS 0.51%via OSV
CVE-2026-86404High· 8.8
2w ago

EAP's Artemis deserialization configuration permits deserialization by default

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() met…

▾ TwilightRed Hat · eap7-activemq-artemisEPSS 0.85%via NVD
CVE-2026-7861Critical· 9.8
2w ago

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.

▾ MidnightNext4Biz Information Technologies Inc. · CSM (Customer Service Management)EPSS 0.56%via NVD
CVE-2026-10196Critical· 9.8
3w ago

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'han…

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'han…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-19887High· 8.8
3w ago

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction)

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). …

▾ Twilightuscnanbu · Welcart e-CommerceEPSS 0.57%via NVD
CVE-2026-52777Critical· 9.4
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

▾ MidnightYesWiki · yeswikiEPSS 0.28%via NVD
CVE-2026-61686High· 7.5
3w ago

SolidInvoice is an open-source invoicing platform

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writa…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-84834Critical· 9.8
3w ago

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

▾ MidnightEPSS 0.56%via NVD
CWE-502 vulnerabilities (CVEs) — page 4 · VulnSea