Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,960 CVEs tagged with CWE-5021,130 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2026-39478

Published Jun 15, 2026

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39474

Published Jun 15, 2026

Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39472

Published Jun 15, 2026

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39471

Published Jun 15, 2026

Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39434

Published Jun 15, 2026

Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-27333

Published Jun 15, 2026

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-27053

Published Jun 15, 2026

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-39006

Published Jun 15, 2026

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-11860

Published Jun 15, 2026

Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in tr…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-12191

Published Jun 14, 2026

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Modul…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-50633

Published Jun 12, 2026

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deploym…

CVSS 8.1 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-50632

Published Jun 12, 2026

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution ca…

CVSS 8.1 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-41699

Published Jun 11, 2026

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53435

Published Jun 10, 2026

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker…

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-52751

Published Jun 10, 2026

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers…

CVSS 8.6 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-10721

Published Jun 10, 2026

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11815

Published Jun 10, 2026

An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability c…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41732

Published Jun 10, 2026

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionall…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40993

Published Jun 10, 2026

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44963

Published Jun 9, 2026

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-48560

Published Jun 9, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2026-45484

Published Jun 9, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort
Showing 226-250 of 2,960 CVEsPage 10 of 119