cwe-502
Safeguard articles tagged "cwe-502" — guides, analysis, and best practices for software supply chain and application security.
77 articles
CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2019-9875 affects Sitecore CMS and Experience Platform (XP) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-03-26.
CVE-2025-24813: Apache Tomcat Path Equivalence Vulnerability
CVE-2025-24813 affects Apache Tomcat and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-04-01.
CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability
CVE-2025-42999 affects SAP NetWeaver and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-05-15.
CVE-2025-24016: Wazuh Server Deserialization of Untrusted Data Vulnerability
CVE-2025-24016 affects Wazuh Wazuh Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-06-10.
CVE-2025-53770: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2025-53770 affects Microsoft SharePoint and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-20.
CVE-2024-8069: Citrix Session Recording Deserialization of Untrusted Data Vulnerability
CVE-2024-8069 affects Citrix Session Recording and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-08-25.
CVE-2025-53690: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
CVE-2025-53690 affects Sitecore Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-04.
CVE-2025-5086: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
CVE-2025-5086 affects Dassault Systèmes DELMIA Apriso and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-11.
CVE-2025-10035: Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
CVE-2025-10035 affects Fortra GoAnywhere MFT and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-29.
CVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
CVE-2025-59287 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-24.
CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
CVE-2025-40551 affects SolarWinds Web Help Desk and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-03.
CVE-2025-49113: RoundCube Webmail Deserialization of Untrusted Data Vulnerability
CVE-2025-49113 affects Roundcube Webmail and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-20.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.