CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 17 of 70
- CVE-2024-40624CRITICALCVSS 9.8EG 9.82024-07-15
TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled cookies.…
- CVE-2024-5488CRITICALCVSS 9.8EG 9.82024-07-09
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, comprom…
- CVE-2024-39705CRITICALCVSS 9.8EG 9.82024-06-27
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
- CVE-2024-5871CRITICALCVSS 9.8EG 9.82024-06-15
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it poss…
- CVE-2024-5671CRITICALCVSS 9.8EG 9.82024-06-14
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.
- CVE-2024-26289CRITICALCVSS 9.8EG 9.82024-05-27
Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.
- CVE-2024-4413CRITICALCVSS 9.8EG 9.82024-05-14
The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Obj…
- CVE-2024-3070CRITICALCVSS 9.8EG 9.82024-05-14
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for u…
- CVE-2024-26579CRITICALCVSS 9.8EG 9.82024-05-08
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 …
- CVE-2023-51576CRITICALCVSS 9.8EG 9.82024-05-03
Voltronic Power ViewPower Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower. Authentication is…
- CVE-2023-39476CRITICALCVSS 9.8EG 9.82024-05-03
Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automat…
- CVE-2023-39475CRITICALCVSS 9.8EG 9.82024-05-03
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of I…
- CVE-2024-1813CRITICALCVSS 9.8EG 9.82024-04-09
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possi…
- CVE-2024-31224CRITICALCVSS 9.8EG 9.82024-04-08
GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution.…
- CVE-2024-27604CRITICALCVSS 9.8EG 9.82024-04-02
Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.
- CVE-2023-51570CRITICALCVSS 9.8EG 9.82024-04-01
Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentic…
- CVE-2024-29433CRITICALCVSS 9.8EG 9.82024-04-01
A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.
- CVE-2024-28861CRITICALCVSS 9.8EG 9.82024-03-22
Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget chain due to dangerous deserialization in `sfNamespacedParam…
- CVE-2024-2054CRITICALCVSS 9.8EG 9.82024-03-21
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
- CVE-2024-28213CRITICALCVSS 9.8EG 9.82024-03-07
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
- CVE-2024-28212CRITICALCVSS 9.8EG 9.82024-03-07
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
- CVE-2024-28211CRITICALCVSS 9.8EG 9.82024-03-07
nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.
- CVE-2024-24302CRITICALCVSS 9.8EG 9.82024-03-03
An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the post…
- CVE-2024-23052CRITICALCVSS 9.8EG 9.82024-02-29
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
- CVE-2023-51518CRITICALCVSS 9.8EG 9.82024-02-27
Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that cou…
- CVE-2023-51389CRITICALCVSS 9.8EG 9.82024-02-22
Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration is used, resulting in a YAML deserialization vulnerability. Version 1.4.1 fixe…
- CVE-2024-23114CRITICALCVSS 9.8EG 9.82024-02-20
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue…
- CVE-2024-23759CRITICALCVSS 9.8EG 9.82024-02-12
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
- CVE-2024-24797CRITICALCVSS 9.8EG 9.82024-02-12
Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.
- CVE-2024-22320CRITICALCVSS 9.8EG 9.82024-02-02
IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerab…
- CVE-2024-23636CRITICALCVSS 9.8EG 9.82024-01-23
SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for …
- CVE-2017-20189CRITICALCVSS 9.8EG 9.82024-01-22
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.
- CVE-2023-6049CRITICALCVSS 9.8EG 9.82024-01-15
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog
- CVE-2023-52200CRITICALCVSS 9.8EG 9.82024-01-08
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Members…
- CVE-2024-0302CRITICALCVSS 9.8EG 9.82024-01-08
A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be ini…
- CVE-2023-49442CRITICALCVSS 9.8EG 9.82024-01-03
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
- CVE-2023-51414CRITICALCVSS 9.8EG 9.82023-12-29
Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.
- CVE-2023-51700CRITICALCVSS 9.8EG 9.82023-12-27
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserializati…
- CVE-2022-34268CRITICALCVSS 9.8EG 9.82023-12-25
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
- CVE-2023-49826CRITICALCVSS 9.8EG 9.82023-12-21
Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a thr…
- CVE-2023-32242CRITICALCVSS 9.8EG 9.82023-12-21
Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.
- CVE-2023-51656CRITICALCVSS 9.8EG 9.82023-12-21
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
- CVE-2023-47507CRITICALCVSS 9.8EG 9.82023-12-20
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.
- CVE-2023-49819CRITICALCVSS 9.8EG 9.82023-12-19
Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.
- CVE-2023-46279CRITICALCVSS 9.8EG 9.82023-12-15
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.
- CVE-2023-29234CRITICALCVSS 9.8EG 9.82023-12-15
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.
- CVE-2023-50252CRITICALCVSS 9.8EG 9.82023-12-12
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially …
- CVE-2023-48967CRITICALCVSS 9.8EG 9.82023-12-04
Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.
- CVE-2023-48887CRITICALCVSS 9.8EG 9.82023-12-01
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
- CVE-2023-48886CRITICALCVSS 9.8EG 9.82023-12-01
A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →