Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,979 CVEs tagged with CWE-5021,140 Critical, 1,435 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2026-66713

Published Jul 28, 2026

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only whe…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-11756

Published Jul 28, 2026

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x coul…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65617

Published Jul 27, 2026

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-63077

Published Jul 27, 2026

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-15962

Published Jul 26, 2026

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. Thi…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-50517

Published Jul 24, 2026

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-21655

Published Jul 23, 2026

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-65497

Published Jul 23, 2026

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65493

Published Jul 23, 2026

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59544

Published Jul 23, 2026

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-16723

Published Jul 23, 2026

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
34.1
Public PoC observed

CVE-2026-61246

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60439

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60373

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60369

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13190

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced pers…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13185

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie co…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47058

Published Jul 21, 2026

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerabilit…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24232

Published Jul 21, 2026

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-64606

Published Jul 21, 2026

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-64608

Published Jul 21, 2026

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-63767

Published Jul 20, 2026

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands b…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6
Showing 1-25 of 2,979 CVEsPage 1 of 120