VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

405 CVEsRSS

GHSA-wg9g-w2j2-8pgrHigh· 7.8
1mo ago

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

▾ Twilightmonai · monaivia GHSA
CVE-2026-63337High· 8.8
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted syst…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.56%via NVD
CVE-2026-59940Critical· 9.8
1mo ago

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general…

▾ Midnightseroval · serovalEPSS 0.81%via NVD
CVE-2026-10035Medium· 6.6
1mo ago

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached t…

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached t…

▾ SunlitEPSS 0.69%via NVD
CVE-2026-16099High· 8.8
1mo ago

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for…

▾ TwilightEPSS 1.1%via NVD
CVE-2025-7639High· 7.1
1mo ago

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of En…

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of En…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-66256High· 7.2
1mo ago

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigge…

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigge…

▾ Twilightapache · shindigEPSS 0.94%via NVD
CVE-2026-73325High· 7.8
1mo ago

Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantiz…

Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantiz…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-59242Medium· 5.4
1mo ago

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user…

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user…

▾ Sunlitapache · airflowEPSS 0.80%via NVD
CVE-2026-58076High· 8.8
1mo ago

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be i…

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be i…

▾ Twilightapache · airflowEPSS 0.92%via NVD
CVE-2026-68756Medium· 6.6
1mo ago

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

▾ SunlitEPSS 0.47%via NVD
CVE-2026-67587High· 8.8
1mo ago

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default…

▾ Twilightapache · airflowEPSS 1.2%via NVD
CVE-2026-67260High· 7.3
1mo ago

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who con…

▾ Twilightapache · airflowEPSS 1.4%via NVD
CVE-2026-15555High· 8.8
1mo ago

A flaw was found in JBoss marshalling

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on …

▾ TwilightRed Hat · org.jboss.eap/wildfly-clustering-infinispan-marshallingEPSS 0.32%via NVD
CVE-2026-70321High· 8.8
1mo ago

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Server Subscription EditionEPSS 1.7%via CVEORG
CVE-2026-63516Medium· 6.5
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 1.9%via CVEORG
CVE-2026-63514High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-65658High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-62912Medium· 6.5
1mo ago

Microsoft Exchange Server Denial of Service Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 2.0%via CVEORG
CVE-2026-65815High· 8.8
1mo ago

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Dynamics 365 (on-premises) version 9.1EPSS 1.7%via CVEORG
CVE-2026-65665High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Server 2019EPSS 1.7%via CVEORG
CVE-2026-65663High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-64901High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-66808High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-66805High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-59124Critical· 9.8
1mo ago

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_appEPSS 1.5%via NVD
CVE-2026-69659None
1mo ago

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:af…

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:af…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-19363Medium· 5.3
1mo ago

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. …

▾ SunlitEPSS 0.67%via NVD
CVE-2026-68772High· 8.0
1mo ago

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attack…

▾ TwilightZenML · ZenMLEPSS 0.76%via NVD
CVE-2026-50515Critical· 9.9
1mo ago

Azure Service Bus Remote Code Execution Vulnerability

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

▾ MidnightMicrosoft · Azure Service BusEPSS 1.7%via CVEORG
CWE-502 vulnerabilities (CVEs) — page 6 · VulnSea