Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,960 CVEs tagged with CWE-5021,130 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2026-49740

Published Jun 9, 2026

TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-8365

Published Jun 9, 2026

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in ver…

CVSS 8.8 · High
evidence mentions
14
Buzz score
42.1

CVE-2026-41855

Published Jun 9, 2026

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverte…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7566

Published Jun 6, 2026

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted in…

CVSS 6.6 · Medium
evidence mentions
9
Buzz score
38.0

CVE-2026-7654

Published Jun 5, 2026

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `un…

CVSS 8.8 · High
evidence mentions
11
Buzz score
39.9

CVE-2026-50589

Published Jun 5, 2026

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service cr…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
35.5
Vendor/product tagsBeta · best-effort

CVE-2026-25551

Published Jun 4, 2026

Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataService…

CVSS 8.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-25550

Published Jun 4, 2026

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.S…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-50076

Published Jun 4, 2026

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class re…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-7888

Published Jun 3, 2026

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restricti…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47065

Published Jun 3, 2026

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PR…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42211

Published Jun 2, 2026

React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34993

Published Jun 2, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code e…

CVSS 6.4 · Medium
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-24237

Published Jun 2, 2026

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code e…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24221

Published Jun 2, 2026

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code e…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-39555

Published Jun 2, 2026

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39551

Published Jun 2, 2026

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39550

Published Jun 2, 2026

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10566

Published Jun 2, 2026

A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipul…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-9330

Published Jun 1, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9319

Published Jun 1, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49121

Published Jun 1, 2026

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that a…

CVSS 9.2 · Critical
evidence mentions
6
Buzz score
38.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-38950

Published Jun 1, 2026

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session direc…

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-10532

Published Jun 1, 2026

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily rest…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-7858

Published Jun 1, 2026

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Mag…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 251-275 of 2,960 CVEsPage 11 of 119