Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,960 CVEs tagged with CWE-5021,130 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2025-71363

Published Jun 30, 2026

picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious p…

CVSS 7.6 · High

CVE-2025-71350

Published Jun 30, 2026

picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files t…

CVSS 7.6 · High

CVE-2025-71349

Published Jun 30, 2026

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers…

CVSS 7.6 · High

CVE-2026-7871

Published Jun 30, 2026

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integri…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13759

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver)…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12578

Published Jun 30, 2026

The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-12240

Published Jun 30, 2026

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and…

CVSS 8.0 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-46386

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the defau…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57527

Published Jun 26, 2026

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbit…

CVSS 8.7 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-56057

Published Jun 26, 2026

Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56055

Published Jun 26, 2026

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-56032

Published Jun 26, 2026

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56031

Published Jun 26, 2026

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-53914

Published Jun 26, 2026

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-71340

Published Jun 25, 2026

picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code…

CVSS 7.6 · High

CVE-2026-46607

Published Jun 25, 2026

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable,…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-56053

Published Jun 25, 2026

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-10043

Published Jun 24, 2026

MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-56121

Published Jun 24, 2026

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gR…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
41.7
Public PoC observed

CVE-2025-71354

Published Jun 24, 2026

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files w…

CVSS 7.6 · High

CVE-2026-54512

Published Jun 23, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-41862

Published Jun 23, 2026

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39253

Published Jun 23, 2026

An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-71376

Published Jun 23, 2026

picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attackers can embed undetected code in…

CVSS 7.6 · High

CVE-2025-71370

Published Jun 23, 2026

picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files…

CVSS 7.6 · High
Showing 101-125 of 2,960 CVEsPage 5 of 119