Vulnerabilities (CVE)

Filtered by CWE-502
Total 2960 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-61168 1 Sigb 1 Pmb 2026-07-05 N/A 9.8 CRITICAL
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
CVE-2025-60889 1 Stellar-group 1 Hpx 2026-07-05 N/A 9.8 CRITICAL
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
CVE-2025-25691 1 Prestashop 1 Prestashop 2026-07-05 N/A 6.5 MEDIUM
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2025-60887 2026-07-05 N/A 5.3 MEDIUM
An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, where Cista does not perform sufficient checks to safeguard against self-referencing pointers and referencing other data within the payload. The leak occurs if the deserialized values are observable by the attacker.
CVE-2025-56422 1 Limesurvey 1 Limesurvey 2026-07-05 N/A 9.8 CRITICAL
A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.
CVE-2025-25692 1 Prestashop 1 Prestashop 2026-07-05 N/A 6.5 MEDIUM
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2024-44902 1 Thinkphp 1 Thinkphp 2026-07-05 N/A 9.8 CRITICAL
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
CVE-2026-13759 1 Ibm 1 Websphere Extreme Scale 2026-07-03 N/A 7.5 HIGH
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs
CVE-2026-7871 1 Langflow 1 Langflow 2026-07-02 N/A 9.8 CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
CVE-2026-55223 2026-07-02 N/A N/A
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them as "properties" assumed safe while they actually call into JDBC drivers. Attackers can thus craft malicious DataSource objects whose property lookups invoke vulnerable drivers, then smuggle them in serialized form to where an application deserializes and auto-resolves bean properties — triggering the attack. This requires a susceptible DataSource/ConnectionPoolDataSource and JDBC driver on the CLASSPATH, plus a carrier that auto-looks-up JavaBean properties on = deserialization, most commonly a collection paired with an Apache commons-beanutils Comparator that sorts by bean properties. c3p0 supplied that susceptible DataSource/ConnectionPoolDataSource, which was an essential component of the trigger. This issue has been fixed in version 0.14.0.
CVE-2026-51947 2026-07-02 N/A 9.8 CRITICAL
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this issue exists because of an incomplete fix for CVE-2026-39253.
CVE-2026-56037 2026-07-02 N/A 8.8 HIGH
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.
CVE-2026-27414 2026-07-02 N/A 8.8 HIGH
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
CVE-2026-24250 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24244 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24251 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24247 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24245 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24243 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24240 2 Linux, Nvidia 2 Linux Kernel, Nemo Megatron Bridge 2026-07-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.