CWE-502
CVEs classified under CWE-502, newest first.
404 CVEsRSS
GHSA-mg57-j93w-g3c7High· 8.1Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx
Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx
CVE-2026-41862High· 8.8Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…
CVE-2026-54512High· 8.1PoCjackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…
CVE-2026-54514Medium· 5.3jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)
A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…
CVE-2026-44795High· 8.5Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
CVE-2026-46607High· 7.8Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
GHSA-fcqg-3mwf-cfcfHigh· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx
Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx
GHSA-8mc5-7w9m-fqv6High· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
GHSA-qvp4-q2p5-22ggHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
CVE-2026-54499High· 7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
GHSA-rpj2-4hq8-938gHigh· 7.8VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
CVE-2026-12569Critical· 9.8CISA KEVA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS…
CVE-2025-69130High· 8.8WordPress Entrepreneur - Booking for Small Businesses WordPress Theme theme < 3.1.5 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Businesses WordPress …
GHSA-rmpp-8wf5-xx5qCritical· 9.8Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
GHSA-j6c9-qvp8-699fCritical· 9.8Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
CVE-2026-10748High· 7.2An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
CVE-2026-48853Critical· 9.2PoCDeserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…
CVE-2026-50633High· 8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …
CVE-2026-50632High· 8.1A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
CVE-2026-49740MediumTYPO3 CMS has Insecure Deserialization via Core API
TYPO3 CMS has Insecure Deserialization via Core API
CVE-2026-41699High· 8.1Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a p…
CVE-2025-27511High· 7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVE-2026-41732High· 8.1JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to tr…
CVE-2026-40993High· 7.3An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of veri…
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of veri…
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-45484High· 8.8Microsoft SharePoint Elevation of Privilege Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-48560Medium· 5.4Microsoft SharePoint Server Spoofing Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-26142Critical· 9.8Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-41855High· 8.1In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…
CVE-2026-45034CriticalPoCPHPSpreadsheet has a patch bypass for CVE-2026-34084
PHPSpreadsheet has a patch bypass for CVE-2026-34084