CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 19 of 70
- CVE-2023-28500CRITICALCVSS 9.8EG 9.82023-04-06
A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a spec…
- CVE-2020-29312CRITICALCVSS 9.8EG 9.82023-04-04
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a ve…
- CVE-2023-28462CRITICALCVSS 9.8EG 9.82023-03-30
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load maliciou…
- CVE-2022-36978CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2022-36977CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2022-36974CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2023-1133CRITICALCVSS 9.8EG 9.82023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the conten…
- CVE-2023-28667CRITICALCVSS 9.8EG 9.82023-03-22
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being s…
- CVE-2023-28115CRITICALCVSS 9.8EG 9.82023-03-17
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `fi…
- CVE-2023-26779CRITICALCVSS 9.8EG 9.82023-03-03
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
- CVE-2022-37936CRITICALCVSS 9.8EG 9.82023-03-01
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
- CVE-2023-27372CRITICALCVSS 9.8EG 9.82023-02-28
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
- CVE-2023-26326CRITICALCVSS 9.8EG 9.82023-02-23
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize …
- CVE-2023-0232CRITICALCVSS 9.8EG 9.82023-02-21
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
- CVE-2022-45982CRITICALCVSS 9.8EG 9.82023-02-08
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- CVE-2023-25135CRITICALCVSS 9.8EG 9.82023-02-03
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling uns…
- CVE-2023-24997CRITICALCVSS 9.8EG 9.82023-02-01
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https:/…
- CVE-2023-24162CRITICALCVSS 9.8EG 9.82023-01-31
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
- CVE-2022-46478CRITICALCVSS 9.8EG 9.82023-01-13
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
- CVE-2022-41778CRITICALCVSS 9.8EG 9.82023-01-13
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized object…
- CVE-2021-32824CRITICALCVSS 9.8EG 9.82023-01-03
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to…
- CVE-2022-4120CRITICALCVSS 9.8EG 9.82022-12-26
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object inje…
- CVE-2021-38241CRITICALCVSS 9.8EG 9.82022-12-16
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
- CVE-2021-33420CRITICALCVSS 9.8EG 9.82022-12-15
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
- CVE-2022-3900CRITICALCVSS 9.8EG 9.82022-12-12
The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection v…
- CVE-2022-44351CRITICALCVSS 9.8EG 9.82022-12-07
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
- CVE-2022-44371CRITICALCVSS 9.8EG 9.82022-12-07
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
- CVE-2022-32224CRITICALCVSS 9.8EG 9.82022-12-05
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL in…
- CVE-2022-46366CRITICALCVSS 9.8EG 9.82022-12-02
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability …
- CVE-2022-45047CRITICALCVSS 9.8EG 9.82022-11-16
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor u…
- CVE-2022-45136CRITICALCVSS 9.8EG 9.82022-11-14
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is…
- CVE-2022-45378CRITICALCVSS 9.8EG 9.82022-11-14
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are avail…
- CVE-2022-44562CRITICALCVSS 9.8EG 9.82022-11-09
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44559CRITICALCVSS 9.8EG 9.82022-11-09
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44558CRITICALCVSS 9.8EG 9.82022-11-09
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44542CRITICALCVSS 9.8EG 9.82022-11-01
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.
- CVE-2022-38142CRITICALCVSS 9.8EG 9.82022-10-31
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to…
- CVE-2022-39312CRITICALCVSS 9.8EG 9.82022-10-25
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the …
- CVE-2022-43019CRITICALCVSS 9.8EG 9.82022-10-19
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
- CVE-2022-39198CRITICALCVSS 9.8EG 9.82022-10-18
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x versio…
- CVE-2022-40889CRITICALCVSS 9.8EG 9.82022-10-18
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
- CVE-2018-18447CRITICALCVSS 9.8EG 9.82022-10-12
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
- CVE-2018-18446CRITICALCVSS 9.8EG 9.82022-10-12
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
- CVE-2022-40314CRITICALCVSS 9.8EG 9.82022-09-30
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
- CVE-2022-36944CRITICALCVSS 9.8EG 9.82022-09-23
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows atta…
- CVE-2022-41237CRITICALCVSS 9.8EG 9.82022-09-21
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
- CVE-2022-38352CRITICALCVSS 9.8EG 9.82022-09-15
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- CVE-2022-29063CRITICALCVSS 9.8EG 9.82022-09-02
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, a…
- CVE-2022-37021CRITICALCVSS 9.8EG 9.82022-08-31
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JM…
- CVE-2022-34668CRITICALCVSS 9.8EG 9.82022-08-29
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confiden…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →