CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 18 of 70
- CVE-2023-47207CRITICALCVSS 9.8EG 9.82023-11-30
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.
- CVE-2023-46990CRITICALCVSS 9.8EG 9.82023-11-20
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
- CVE-2023-46302CRITICALCVSS 9.8EG 9.82023-11-20
Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail/CVE-2022-1471 . Apache Submarine uses JAXRS to define REST endpoints. In order to handl…
- CVE-2023-44353CRITICALCVSS 9.8EG 9.82023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user int…
- CVE-2023-44351CRITICALCVSS 9.8EG 9.82023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user int…
- CVE-2023-44350CRITICALCVSS 9.8EG 9.82023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user int…
- CVE-2023-47130CRITICALCVSS 9.8EG 9.82023-11-14
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compr…
- CVE-2023-47248CRITICALCVSS 9.8EG 9.82023-11-09
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for exam…
- CVE-2023-46817CRITICALCVSS 9.8EG 9.82023-11-03
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthe…
- CVE-2023-47204CRITICALCVSS 9.8EG 9.82023-11-02
Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.
- CVE-2023-47174CRITICALCVSS 9.8EG 9.82023-10-31
Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway…
- CVE-2023-4402CRITICALCVSS 9.8EG 9.82023-10-20
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a …
- CVE-2023-35084CRITICALCVSS 9.8EG 9.82023-10-18
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.
- CVE-2023-43981CRITICALCVSS 9.8EG 9.82023-10-05
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.
- CVE-2023-5391CRITICALCVSS 9.8EG 9.82023-10-04
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
- CVE-2023-44273CRITICALCVSS 9.8EG 9.82023-09-28
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
- CVE-2023-43291CRITICALCVSS 9.8EG 9.82023-09-27
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
- CVE-2023-40619CRITICALCVSS 9.8EG 9.82023-09-20
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is …
- CVE-2023-5016CRITICALCVSS 9.8EG 9.82023-09-17
A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.getConnection of the file src/main/java/org/spiderflow/controller/DataSourceController.jav…
- CVE-2023-38204CRITICALCVSS 9.8EG 9.82023-09-14
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does…
- CVE-2020-19559CRITICALCVSS 9.8EG 9.82023-09-11
An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.
- CVE-2023-41330CRITICALCVSS 9.8EG 9.82023-09-06
knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution throug…
- CVE-2023-0925CRITICALCVSS 9.8EG 9.82023-09-06
Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high po…
- CVE-2023-40571CRITICALCVSS 9.8EG 9.82023-08-25
weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-fram…
- CVE-2023-3259CRITICALCVSS 9.8EG 9.82023-08-14
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to …
- CVE-2023-36480CRITICALCVSS 9.8EG 9.82023-08-04
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects…
- CVE-2023-38647CRITICALCVSS 9.8EG 9.82023-07-26
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can…
- CVE-2023-37895CRITICALCVSS 9.8EG 9.82023-07-25
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-…
- CVE-2023-26512CRITICALCVSS 9.8EG 9.82023-07-17
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code exec…
- CVE-2023-25770CRITICALCVSS 9.8EG 9.82023-07-13
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-34347CRITICALCVSS 9.8EG 9.82023-07-10
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
- CVE-2023-28323CRITICALCVSS 9.8EG 9.82023-07-01
A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities…
- CVE-2023-31222CRITICALCVSS 9.8EG 9.82023-06-29
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima syste…
- CVE-2023-33299CRITICALCVSS 9.8EG 9.82023-06-23
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server commun…
- CVE-2023-35839CRITICALCVSS 9.8EG 9.82023-06-19
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
- CVE-2023-33496CRITICALCVSS 9.8EG 9.82023-06-07
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
- CVE-2020-36727CRITICALCVSS 9.8EG 9.82023-06-07
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization…
- CVE-2020-36726CRITICALCVSS 9.8EG 9.82023-06-07
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to injec…
- CVE-2020-36718CRITICALCVSS 9.8EG 9.82023-06-07
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attack…
- CVE-2023-33963CRITICALCVSS 9.8EG 9.82023-06-01
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed…
- CVE-2023-27068CRITICALCVSS 9.8EG 9.82023-05-23
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
- CVE-2023-31890CRITICALCVSS 9.8EG 9.82023-05-16
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.
- CVE-2023-1650CRITICALCVSS 9.8EG 9.82023-05-08
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
- CVE-2023-1967CRITICALCVSS 9.8EG 9.82023-04-27
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.
- CVE-2023-20853CRITICALCVSS 9.8EG 9.82023-04-27
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perf…
- CVE-2023-20852CRITICALCVSS 9.8EG 9.82023-04-27
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary syst…
- CVE-2023-20864CRITICALCVSS 9.8EG 9.82023-04-20
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
- CVE-2021-28254CRITICALCVSS 9.8EG 9.82023-04-19
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
- CVE-2023-29216CRITICALCVSS 9.8EG 9.82023-04-10
In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading t…
- CVE-2023-29215CRITICALCVSS 9.8EG 9.82023-04-10
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote c…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →