← Back to feed Search feed

CWE-502 Deserialization vulnerabilities

51 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-70416Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticaCRITICAL10.058%ileNVD2026-09-16
CVE-2026-87719GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3CRITICAL9.948%ileNVD2026-09-12
CVE-2026-82845The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserCRITICAL9.929%ileNVD2026-09-12
CVE-2026-20307A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execCRITICAL9.960%ileNVD2026-09-16
CVE-2026-78006The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includingCRITICAL9.854%ileNVD2026-09-12
CVE-2026-62379Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PCRITICAL9.850%ileNVD2026-09-15
CVE-2025-59953LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and priorCRITICAL9.851%ileNVD2026-09-16
CVE-2026-20242A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could CRITICAL9.849%ileNVD2026-09-16
CVE-2025-66455LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and priorCRITICAL9.8NVD2026-09-18
CVE-2026-81657IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system CRITICAL9.8NVD2026-09-18
CVE-2026-82340IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflCRITICAL9.8NVD2026-09-18
CVE-2026-54752NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The valiCRITICAL9.629%ileNVD2026-09-17
CVE-2026-90919LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_regCRITICAL9.362%ileNVD2026-09-14
CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to executeCRITICAL9.351%ileNVD2026-09-14
CVE-2023-54398Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageSCRITICAL9.349%ileNVD2026-09-15
CVE-2026-91939Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowingCRITICAL9.347%ileNVD2026-09-15
CVE-2026-93467The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execuCRITICAL9.343%ileNVD2026-09-18
CVE-2026-45051Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialCRITICAL9.242%ileNVD2026-09-15
CVE-2026-62263Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize apCRITICAL9.245%ileNVD2026-09-15
CVE-2026-46495OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/CRITICAL9.253%ileNVD2026-09-15
CVE-2026-92785Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist valCRITICAL9.230%ileNVD2026-09-16
CVE-2026-76834b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array objeCRITICAL9.256%ileNVD2026-09-17
CVE-2026-20211A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlyiCRITICAL9.145%ileNVD2026-09-16
CVE-2026-20341A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authentiCRITICAL9.138%ileNVD2026-09-16
CVE-2026-78175The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all vHIGH8.847%ileNVD2026-09-12
CVE-2026-61701Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 untilHIGH8.843%ileNVD2026-09-14
CVE-2026-13293IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.846%ileNVD2026-09-14
CVE-2026-12728IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.849%ileNVD2026-09-15
CVE-2026-20340A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commandsHIGH8.852%ileNVD2026-09-16
CVE-2026-54916NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abseHIGH8.835%ileNVD2026-09-17
CVE-2026-17086The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object IHIGH8.858%ileNVD2026-09-18
CVE-2026-72649Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code ExecutionHIGH8.846%ileMicrosoft2026-09-08
CVE-2026-63639Valkey: UAF in stream deserialization may lead to remote code executionHIGH8.858%ileMicrosoft2026-08-11
CVE-2026-90777ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrHIGH8.742%ileNVD2026-09-13
CVE-2026-11729IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.522%ileNVD2026-09-15
CVE-2026-84099The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that HIGH8.119%ileNVD2026-09-12
CVE-2026-28364In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables reHIGH7.912%ileMicrosoft2026-02-10
CVE-2026-17156IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to exHIGH7.84%ileNVD2026-09-14
CVE-2026-17416IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to exHIGH7.84%ileNVD2026-09-14
CVE-2026-45794Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS cHIGH7.743%ileNVD2026-09-15
CVE-2026-62997Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PHIGH7.734%ileNVD2026-09-16
CVE-2026-93872Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the commentHIGH7.7NVD2026-09-18
CVE-2026-10751IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicatiHIGH7.5NVD2026-09-18
CVE-2026-90472msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deMEDIUM6.927%ileNVD2026-09-12
CVE-2026-11711IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service componenMEDIUM6.5NVD2026-09-18
CVE-2026-88976Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.MEDIUM6.117%ileNVD2026-09-16
CVE-2026-90614A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_modeMEDIUM5.316%ileNVD2026-09-14
CVE-2026-49400October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, thLOW3.38%ileNVD2026-09-14
CVE-2026-90575A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/loginLOW2.939%ileNVD2026-09-13
CVE-2026-90490A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the componeLOW2.133%ileNVD2026-09-13
CVE-2026-91842A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert oLOW1.230%ileNVD2026-09-15