Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,960 CVEs tagged with CWE-5021,130 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2026-45360

Published Jun 1, 2026

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-42359

Published Jun 1, 2026

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-10042

Published May 29, 2026

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module,…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2025-11993

Published May 29, 2026

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' paramet…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-9828

Published May 28, 2026

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restr…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-37579

Published May 28, 2026

An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47161

Published May 27, 2026

RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'p…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45134

Published May 27, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48919

Published May 27, 2026

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48917

Published May 27, 2026

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44843

Published May 26, 2026

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24162

Published May 26, 2026

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability mig…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-45247

Published May 26, 2026

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code exe…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
65.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-9497

Published May 25, 2026

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulat…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-4372

Published May 24, 2026

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-45659

Published May 22, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
22
Buzz score
79.6
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-41104

Published May 22, 2026

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9291

Published May 22, 2026

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-39832

Published May 22, 2026

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently s…

CVSS 9.1 · Critical
evidence mentions
31
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-8135

Published May 21, 2026

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator wit…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48207

Published May 21, 2026

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration a…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24216

Published May 20, 2026

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execu…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-7637

Published May 20, 2026

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCAT…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-24163

Published May 20, 2026

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24142

Published May 20, 2026

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, d…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 276-300 of 2,960 CVEsPage 12 of 119