VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

404 CVEsRSS

CVE-2026-19795Medium· 6.2
3w ago

Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads

Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializin…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-84753Critical· 9.8PoC
3w ago

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

▾ AbyssalEPSS 0.56%via NVD
CVE-2026-84650High· 8.8
3w ago

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized,…

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized,…

▾ Twilightjenkins · jenkinsEPSS 0.47%via NVD
CVE-2026-84646Medium· 4.3
3w ago

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

▾ Sunlitjenkins · jenkinsEPSS 0.34%via NVD
CVE-2026-84202High· 8.8
3w ago

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files…

▾ TwilightEPSS 0.68%via NVD
CVE-2026-71981High· 8.8PoC
3w ago

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…

▾ MidnightEPSS 0.97%via NVD
CVE-2026-83557Medium· 5.6
3w ago

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe bas…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.71%via NVD
GHSA-gqvg-gmmx-x4hmHigh· 8.8
3w ago

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

▾ Twilightmlflow · mlflowvia GHSA
CVE-2026-81319None
4w ago

Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during d…

Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during d…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-76547Medium· 6.6
4w ago

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The …

▾ SunlitEPSS 0.42%via NVD
CVE-2026-55220Critical
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.68%via NVD
CVE-2026-10036High· 8.8PoC
1mo ago

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enu…

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enu…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-47878Medium· 5.6
1mo ago

DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowli…

DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowli…

▾ Sunlitbroadcom · spring_batchEPSS 0.35%via NVD
CVE-2026-47856Medium· 6.3
1mo ago

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration…

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration…

▾ Sunlitvmware · spring_integrationEPSS 0.31%via NVD
CVE-2026-59307High· 8.0
1mo ago

An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integratio…

An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integratio…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-51106Critical· 9.3
1mo ago

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component

▾ MidnightEPSS 0.40%via NVD
CVE-2026-80428Critical· 9.8PoC
1mo ago

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

▾ AbyssalEPSS 4.5%via NVD
CVE-2026-56095High· 7.7
1mo ago

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object t…

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object t…

▾ TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.32%via NVD
CVE-2026-76843High· 7.8
1mo ago

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model …

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model …

▾ TwilightEPSS 0.38%via NVD
CVE-2026-40877High· 8.7
1mo ago

Combodo iTop is a web-based IT service management tool

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.53%via NVD
CVE-2026-4703Critical· 9.8
1mo ago

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This ma…

▾ MidnightEPSS 0.90%via NVD
CVE-2026-71513High· 8.8
1mo ago

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables …

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables …

▾ Twilightnltk · nltkEPSS 1.1%via NVD
CVE-2026-77646None
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

▾ SunlitEPSS 0.44%via NVD
CVE-2026-77645None
1mo ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

▾ SunlitEPSS 0.56%via NVD
CVE-2026-69836Critical· 10.0PoC
1mo ago

Microsoft Entra ID Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Microsoft EntraEPSS 1.5%via CVEORG
CVE-2026-76850Critical· 9.8PoC
1mo ago

LMDeploy deserializes disaggregated-serving peer messages with pickle

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received…

▾ AbyssalInternLM · lmdeployEPSS 1.3%via NVD
CVE-2026-44901High· 8.4
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a…

▾ Twilightwazuh · wazuhEPSS 0.74%via NVD
CVE-2026-60412High· 7.8
1mo ago

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core)

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · outside_in_technologyEPSS 0.32%via NVD
CVE-2026-60392High· 7.8
1mo ago

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK)

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated atta…

▾ Twilightoracle · outside_in_technologyEPSS 0.32%via NVD
GHSA-qxq5-qhx6-94qwHigh· 7.8
1mo ago

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

▾ Twilightmonai · monaivia GHSA
CWE-502 vulnerabilities (CVEs) — page 5 · VulnSea