CWE-502 · 3,045 records
Deserialization of untrusted data
Why does it happen?
Data received over the network is deserialized into the language’s native object format without verifying its source. Code paths inside the object can be triggered during deserialization.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
payload = sock.recv(65536)job = pickle.loads(payload)Fixed
payload = sock.recv(65536)if not hmac.compare_digest(sign(payload), header_sig): raise PermissionError("invalid signature")job = JobSchema.validate(json.loads(payload))How to prevent it
- 01Use data-only formats (such as JSON) for network messages.
- 02Verify the message source with a signature or mutual TLS.
- 03Validate deserialized data against a schema.
CVEs in this class
3,045 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-55182Weaponized | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Critical10.0 | KEV | 99.8% | Dec 3, 2025 |
99Now | CVE-2021-35464Weaponized | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.forgerock · access management · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 22, 2021 |
99Now | CVE-2025-53770Weaponized | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 19, 2025 |
99Now | CVE-2023-29300Weaponized | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 12, 2023 |
99Now | CVE-2025-59287Weaponized | Windows Server Update Service (WSUS) Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-502 | Critical9.8 | KEV | 100.0% | Oct 14, 2025 |
99Now | CVE-2022-47986Weaponized | IBM Aspera Faspex code executionibm · aspera faspex · CWE-502 | Critical9.8 | KEV | 100.0% | Feb 17, 2023 |
99Now | CVE-2018-2628Weaponized | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).oracle · weblogic server · CWE-502 | Critical9.8 | KEV | 100.0% | Apr 18, 2018 |
99Now | CVE-2020-10189Weaponized | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImagezohocorp · manageengine desktop central · CWE-502 | Critical9.8 | KEV | 99.9% | Mar 6, 2020 |
99Now | CVE-2022-35405Weaponized | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution.zohocorp · manageengine access manager plus · CWE-502 | Critical9.8 | KEV | 99.9% | Jul 19, 2022 |
99Now | CVE-2020-7961Weaponized | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web serliferay · liferay portal · CWE-502 | Critical9.8 | KEV | 99.9% | Mar 20, 2020 |
99Now | CVE-2023-46604Weaponized | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Critical9.8 | KEV | 99.9% | Oct 27, 2023 |
99Now | CVE-2019-18935Weaponized | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.telerik · ui for asp.net ajax · CWE-502 | Critical9.8 | KEV | 99.7% | Dec 11, 2019 |
99Now | CVE-2017-1000353Weaponized | Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.jenkins · jenkins · CWE-502 | Critical9.8 | KEV | 99.7% | Jan 29, 2018 |
98Now | CVE-2018-1000861Weaponized | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/corjenkins · jenkins · CWE-502 | Critical9.8 | KEV | 98.3% | Dec 10, 2018 |
98Now | CVE-2015-7450Weaponized | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products alloibm · sterling b2b integrator · CWE-502 | Critical9.8 | KEV | 97.8% | Jan 2, 2016 |
98Now | CVE-2021-42237Weaponized | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achisitecore · experience platform · CWE-502 | Critical9.8 | KEV | 97.6% | Nov 5, 2021 |
98Now | CVE-2020-2555Weaponized | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).oracle · access manager · CWE-502 | Critical9.8 | KEV | 97.1% | Jan 15, 2020 |
98Now | CVE-2023-38203Weaponized | Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCEadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 97.1% | Jul 20, 2023 |
98Now | CVE-2015-4852Weaponized | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitraryoracle · virtual desktop infrastructure · CWE-502 | Critical9.8 | KEV | 96.0% | Nov 18, 2015 |
98Now | CVE-2019-10068Weaponized | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.kentico · xperience · CWE-502 | Critical9.8 | KEV | 95.1% | Mar 26, 2019 |
97Now | CVE-2025-24016Weaponized | Remote code execution in Wazuh serverwazuh · wazuh · CWE-502 | Critical9.9 | KEV | 93.8% | Feb 10, 2025 |
96Now | CVE-2017-12149Weaponized | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnredhat · jboss enterprise application platform · CWE-502 | Critical9.8 | KEV | 90.7% | Oct 4, 2017 |
96Now | CVE-2017-3066Weaponized | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializaadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 90.6% | Apr 27, 2017 |
96Now | CVE-2024-40711Weaponized | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).veeam · veeam backup \& replication · CWE-502 | Critical9.8 | KEV | 90.4% | Sep 7, 2024 |
96Now | CVE-2026-63077Weaponized | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocoljetbrains · teamcity · CWE-502 | Critical9.8 | KEV | 89.6% | Jul 27, 2026 |
- CVE-2025-55182100Now
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
CriticalCVSS 10.0KEVWeaponizedEPSS 100%facebook · reactDec 3, 2025
- CVE-2021-3546499Now
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%forgerock · access managementJul 22, 2021
- CVE-2025-5377099Now
Microsoft SharePoint Server Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · sharepoint serverJul 19, 2025
- CVE-2023-2930099Now
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionJul 12, 2023
- CVE-2025-5928799Now
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows server 2012Oct 14, 2025
- CVE-2022-4798699Now
IBM Aspera Faspex code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ibm · aspera faspexFeb 17, 2023
- CVE-2018-262899Now
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · weblogic serverApr 18, 2018
- CVE-2020-1018999Now
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine desktop centralMar 6, 2020
- CVE-2022-3540599Now
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine access manager plusJul 19, 2022
- CVE-2020-796199Now
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web ser
CriticalCVSS 9.8KEVWeaponizedEPSS 100%liferay · liferay portalMar 20, 2020
- CVE-2023-4660499Now
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · activemqOct 27, 2023
- CVE-2019-1893599Now
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%telerik · ui for asp.net ajaxDec 11, 2019
- CVE-2017-100035399Now
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%jenkins · jenkinsJan 29, 2018
- CVE-2018-100086198Now
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor
CriticalCVSS 9.8KEVWeaponizedEPSS 98%jenkins · jenkinsDec 10, 2018
- CVE-2015-745098Now
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo
CriticalCVSS 9.8KEVWeaponizedEPSS 98%ibm · sterling b2b integratorJan 2, 2016
- CVE-2021-4223798Now
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi
CriticalCVSS 9.8KEVWeaponizedEPSS 98%sitecore · experience platformNov 5, 2021
- CVE-2020-255598Now
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · access managerJan 15, 2020
- CVE-2023-3820398Now
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 97%adobe · coldfusionJul 20, 2023
- CVE-2015-485298Now
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary
CriticalCVSS 9.8KEVWeaponizedEPSS 96%oracle · virtual desktop infrastructureNov 18, 2015
- CVE-2019-1006898Now
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.
CriticalCVSS 9.8KEVWeaponizedEPSS 95%kentico · xperienceMar 26, 2019
- CVE-2025-2401697Now
Remote code execution in Wazuh server
CriticalCVSS 9.9KEVWeaponizedEPSS 94%wazuh · wazuhFeb 10, 2025
- CVE-2017-1214996Now
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn
CriticalCVSS 9.8KEVWeaponizedEPSS 91%redhat · jboss enterprise application platformOct 4, 2017
- CVE-2017-306696Now
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa
CriticalCVSS 9.8KEVWeaponizedEPSS 91%adobe · coldfusionApr 27, 2017
- CVE-2024-4071196Now
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
CriticalCVSS 9.8KEVWeaponizedEPSS 90%veeam · veeam backup \& replicationSep 7, 2024
- CVE-2026-6307796Now
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CriticalCVSS 9.8KEVWeaponizedEPSS 90%jetbrains · teamcityJul 27, 2026