← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Fory
Aug 8, 2026
Aug 7, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic...Show more
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.Show less
-
-
Aug 26, 2026
Aug 7, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via a...Show more
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.Show less
1Microsoft
1Azure Service Bus
Aug 7, 2026
Aug 7, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
1Apache
1Cxf
Aug 7, 2026
Aug 6, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destinati...Show more
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.Show less
-
-
Aug 31, 2026
Aug 5, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path...Show more
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.Show less
-
-
Aug 26, 2026
Aug 5, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only s...Show more
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to comments (the default setting in plugins/comments/comments.setup.php).Show less