VulnSea

CWE-502

CVEs classified under CWE-502, newest first.

405 CVEsRSS

CVE-2026-61484Critical· 9.8
1mo ago

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Us…

▾ Midnightapache · lucyEPSS 0.81%via NVD
CVE-2026-70554Critical· 9.8
1mo ago

MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without vali…

▾ MidnightMaxSite · MaxSite CMSEPSS 1.2%via CVEORG
CVE-2026-69098Critical· 9.8PoC
1mo ago

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type_…

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type_…

▾ AbyssalEPSS 0.91%via NVD
CVE-2026-3245High· 7.5
1mo ago

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

▾ TwilightEPSS 0.71%via NVD
CVE-2026-68771Critical· 9.8PoC
1mo ago

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

▾ AbyssalComfy-Org · ComfyUIEPSS 1.1%via NVD
CVE-2026-63077Critical· 9.8CISA KEVPoC
2mo ago

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

▾ HadalJetBrains · TeamCityEPSS 9.8%via CVEORG
CVE-2026-15962High· 8.8
2mo ago

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subs…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-50517Critical· 9.9
2mo ago

Microsoft M365 Copilot Remote Code Execution Vulnerability

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

▾ MidnightMicrosoft · Microsoft 365 CopilotEPSS 1.7%via CVEORG
CVE-2026-55223Medium
2mo ago

c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets

c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets

▾ Sunlitmchange · com.mchange:c3p0EPSS 0.48%via GHSA
CVE-2026-47058High· 7.4
2mo ago

Vulnerability in Oracle Java SE (component: Scripting)

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via …

▾ TwilightRed Hat · Red Hat OpenJDK 11 ELS for RHEL 8EPSS 0.39%via NVD
CVE-2026-45162High· 8.0
2mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restri…

▾ TwilightEPSS 0.99%via NVD
CVE-2026-58659High· 7.8
2mo ago

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.63%via NVD
CVE-2026-24220Medium· 6.4
2mo ago

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to …

▾ Sunlitnvidia · tensorrt-llmEPSS 0.33%via NVD
CVE-2026-55009High· 7.8
2mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 2.5%via CVEORG
CVE-2026-54118Critical· 9.8
2mo ago

Microsoft SQL Server Remote Code Execution Vulnerability

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Microsoft SQL Server 2016 Service Pack 3 (GDR)EPSS 1.5%via CVEORG
CVE-2026-54117Critical· 9.8
2mo ago

Microsoft SQL Server Remote Code Execution Vulnerability

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Microsoft SQL Server 2025 (CU 6)EPSS 1.5%via CVEORG
CVE-2026-50522Critical· 9.8CISA KEVPoC
2mo ago

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

▾ HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 3.0%via CVEORG
CVE-2026-50649High· 7.8
2mo ago

.NET Remote Code Execution Vulnerability

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 4.0%via CVEORG
CVE-2026-50646High· 7.8
2mo ago

.NET Framework Remote Code Execution Vulnerability

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 4.0%via CVEORG
CVE-2026-50509High· 7.8
2mo ago

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 3.5%via CVEORG
CVE-2026-55944Critical· 9.8
2mo ago

Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Microsoft Dynamics NAV 2018EPSS 1.5%via CVEORG
CVE-2026-58644Critical· 9.8CISA KEVPoC
2mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · sharepoint_serverEPSS 16%via NVD
CVE-2026-50652High· 7.5
2mo ago

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Azure Active DirectoryEPSS 1.7%via NVD
CVE-2026-15535Medium· 6.3
2mo ago

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Exe…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-15531Medium· 5.3
2mo ago

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipu…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-15529Medium· 6.3
2mo ago

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…

▾ Sunlitpyod · pyodEPSS 0.44%via NVD
CVE-2026-58281High· 8.3
2mo ago

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.96%via NVD
CVE-2026-54469High· 8.8
2mo ago

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary com…

▾ Twilightdell · unisphere_for_powermaxEPSS 0.86%via NVD
CVE-2026-55175High· 7.5
2mo ago

Spinnaker is an open source, multi-cloud continuous delivery platform

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco ma…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-54071High· 7.8
2mo ago

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

▾ TwilightBabelDOC · BabelDOCEPSS 0.38%via GHSA
CWE-502 vulnerabilities (CVEs) — page 7 · VulnSea