Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,960 CVEs tagged with CWE-5021,130 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2026-57677

Published Jul 2, 2026

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57621

Published Jul 2, 2026

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56037

Published Jul 2, 2026

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-27414

Published Jul 2, 2026

Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-27060

Published Jul 2, 2026

Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-55153

Published Jul 1, 2026

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementat…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14265

Published Jul 1, 2026

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the…

CVSS 7.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-51947

Published Jul 1, 2026

An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to e…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-57516

Published Jul 1, 2026

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar a…

CVSS 8.6 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-58127

Published Jul 1, 2026

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any au…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-58126

Published Jul 1, 2026

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .N…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-58025

Published Jul 1, 2026

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24251

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulner…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24250

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lea…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24247

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24245

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24244

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24243

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24240

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-10538

Published Jul 1, 2026

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and C…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56700

Published Jun 30, 2026

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Ses…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-55223

Published Jun 30, 2026

c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC s…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-71374

Published Jun 30, 2026

picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to execute arbitrary code. Remote…

CVSS 7.6 · High

CVE-2025-71371

Published Jun 30, 2026

picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass pickle…

CVSS 7.6 · High

CVE-2025-71368

Published Jun 30, 2026

picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft ma…

CVSS 7.6 · High
Showing 76-100 of 2,960 CVEsPage 4 of 119