Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

3,061 CVEs tagged with CWE-5021,173 Critical, 1,473 High, 343 Medium, 72 Low, 0 Unrated.

CVE-2026-50522

Published Jul 14, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
evidence mentions
54
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-12583

Published Jul 14, 2026

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-58233

Published Jul 14, 2026

SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s libr…

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59521

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a throu…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59518

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57770

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <=…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57744

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a th…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57738

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57724

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57713

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57371

Published Jul 13, 2026

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15535

Published Jul 13, 2026

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file re…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-15531

Published Jul 13, 2026

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_ne…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-15529

Published Jul 13, 2026

A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
33.5

CVE-2026-58281

Published Jul 11, 2026

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS 8.3 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-55175

Published Jul 10, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize ba…

CVSS 7.5 · High
evidence mentions
11
Buzz score
29.9
Vendor/product tagsBeta · best-effort

CVE-2026-44795

Published Jul 10, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization wh…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-54469

Published Jul 10, 2026

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potent…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59827

Published Jul 9, 2026

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection,…

CVSS 9.9 · Critical
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-54499

Published Jul 8, 2026

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.mod…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33264

Published Jul 7, 2026

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2026-43825

Published Jul 6, 2026

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-46590

Published Jul 6, 2026

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifec…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 126-150 of 3,061 CVEsPage 6 of 123