Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-502

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,972
Assigned CVEs
27th
Commonality Rank
8.7
Avg CVSS
2.5%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-502 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2003
22 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

2,972 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-55182CRITICAL
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve
Dec 3, 202510.099YESYES
CVE-2025-59287CRITICAL
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Oct 14, 20259.899YESYES
CVE-2025-53770CRITICAL
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for
Jul 20, 20259.899YESYES
CVE-2025-49113HIGH
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions
Jun 2, 20258.899YESYES
CVE-2025-24813CRITICAL
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
CVE-2021-44228CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
CVE-2021-35464CRITICAL
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and r
Jul 22, 20219.899YESYES
CVE-2020-7961CRITICAL
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Mar 20, 20209.899YESYES
CVE-2020-10189CRITICAL
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is relat
Mar 6, 20209.899YESYES
CVE-2020-0618HIGH
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remo
Feb 11, 20208.899YESYES
View all 2,972 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
16%
6.0-6.9
21%
26%
7.0-7.9
29%
11%
8.0-8.9
43%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
74 CVEs
2.5% of CVEs· 96th percentile
Metasploit
76 CVEs
2.6% of CVEs· 94th percentile
Nuclei
87 CVEs
2.9% of CVEs· 92nd percentile
ExploitDB
68 CVEs
2.3% of CVEs· 89th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products