Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,974 CVEs tagged with CWE-5021,137 Critical, 1,433 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2026-24162

Published May 26, 2026

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability mig…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-45247

Published May 26, 2026

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code exe…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
65.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-9497

Published May 25, 2026

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulat…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-4372

Published May 24, 2026

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-45659

Published May 22, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
22
Buzz score
79.6
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-41104

Published May 22, 2026

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9291

Published May 22, 2026

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-39832

Published May 22, 2026

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently s…

CVSS 9.1 · Critical
evidence mentions
33
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-8135

Published May 21, 2026

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator wit…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48207

Published May 21, 2026

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration a…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24216

Published May 20, 2026

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execu…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-7637

Published May 20, 2026

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCAT…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-24163

Published May 20, 2026

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24142

Published May 20, 2026

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, d…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-33255

Published May 20, 2026

NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-6009

Published May 19, 2026

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31072

Published May 19, 2026

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The un…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.4

CVE-2025-51427

Published May 19, 2026

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet'…

CVSS 7.3 · High
evidence mentions
6
Buzz score
32.5

CVE-2026-43633

Published May 19, 2026

HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows…

CVSS 9.5 · Critical
evidence mentions
5
Buzz score
29.4

CVE-2026-8727

Published May 19, 2026

The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrar…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46725

Published May 19, 2026

The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted ser…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-33233

Published May 19, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deseriali…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-26978

Published May 18, 2026

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to comprom…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45829

Published May 18, 2026

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
40.8

CVE-2026-7304

Published May 18, 2026

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded v…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 301-325 of 2,974 CVEsPage 13 of 119