← Back to feed Search feed

CWE-502 Deserialization vulnerabilities

20 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-65883Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A foCRITICAL10.040%ileNVD2026-07-29
CVE-2026-14512IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whiCRITICAL9.842%ileNVD2026-07-28
CVE-2026-12118IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary coCRITICAL9.840%ileNVD2026-07-30
CVE-2026-15969SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylCRITICAL9.859%ileNVD2026-07-30
CVE-2026-15976SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wiCRITICAL9.826%ileNVD2026-07-30
CVE-2026-68771ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticCRITICAL9.346%ileNVD2026-07-31
CVE-2026-69098kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows CRITICAL9.3NVD2026-08-04
CVE-2026-54365CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unautheHIGH8.712%ileNVD2026-07-30
CVE-2026-11536IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conneHIGH8.526%ileNVD2026-07-30
CVE-2026-58163Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue afHIGH8.348%ileNVD2026-07-29
CVE-2026-14974IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code causedHIGH8.129%ileNVD2026-07-28
CVE-2026-18642Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock HIGH7.83%ileNVD2026-08-03
CVE-2026-57859e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows aHIGH7.733%ileNVD2026-07-30
CVE-2026-3245A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.HIGH7.715%ileNVD2026-08-03
CVE-2026-1360The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includHIGH7.544%ileNVD2026-07-30
CVE-2026-12720The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data HIGH7.523%ileNVD2026-07-31
CVE-2026-15920An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(MEDIUM5.1NVD2026-08-04
CVE-2026-16297The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-imporMEDIUM4.114%ileNVD2026-08-03
CVE-2026-16062The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-coUNKNOWN11%ileNVD2026-08-02
CVE-2025-15672The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializaUNKNOWN13%ileNVD2026-08-03