Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-502'

View all threats tagged with 'cwe-502'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-502

Threats Tagged 'cwe-502'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-16267: CWE-502 Deserialization of Untrusted Data in NewslettersCVE-2026-16267
0

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

Join the discussion
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying… (CVE-2026-71559)CVE-2026-71559
0

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

Join the discussion
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. (CVE-2026-71560)CVE-2026-71560
0

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.

Join the discussion
CVE-2026-71560: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache ForyCVE-2026-71560
0

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.

Join the discussion
CVE-2026-71559: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache ForyCVE-2026-71559
0

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

Join the discussion
CVE-2026-71558: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache ForyCVE-2026-71558
0

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.

Join the discussion
CVE-2026-16258: CWE-502 Deserialization of Untrusted Data in Ajax Search LiteCVE-2026-16258
0

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.

Join the discussion
CVE-2026-50515: CWE-502: Deserialization of Untrusted Data in Microsoft Azure Service BusCVE-2026-50515
0

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

Join the discussion
CVE-2026-50515: CWE-502: Deserialization of Untrusted Data in Microsoft Azure Service BusCVE-2026-50515
0

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

Join the discussion
CVE-2026-65581: CWE-502 Deserialization of Untrusted Data in Axiomthemes AI ANNCVE-2026-65581
0

Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

Join the discussion

Showing 1 to 10 of 83 results

Filters:Tag: cwe-502
Page 1 of 9
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses