CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 20 of 70
- CVE-2022-29805CRITICALCVSS 9.8EG 9.82022-08-19
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
- CVE-2022-35223CRITICALCVSS 9.8EG 9.82022-08-02
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthent…
- CVE-2022-33318CRITICALCVSS 9.8EG 9.82022-07-20
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97…
- CVE-2022-24082CRITICALCVSS 9.8EG 9.82022-07-19
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the…
- CVE-2022-2437CRITICALCVSS 9.8EG 9.82022-07-18
The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthent…
- CVE-2021-41419CRITICALCVSS 9.8EG 9.82022-07-18
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
- CVE-2022-35857CRITICALCVSS 9.8EG 9.82022-07-13
kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.
- CVE-2022-35411CRITICALCVSS 9.8EG 9.82022-07-08
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the …
- CVE-2022-31605CRITICALCVSS 9.8EG 9.82022-07-01
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to c…
- CVE-2022-31604CRITICALCVSS 9.8EG 9.82022-07-01
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged n…
- CVE-2022-33107CRITICALCVSS 9.8EG 9.82022-06-29
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted …
- CVE-2022-25863CRITICALCVSS 9.8EG 9.82022-06-10
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input s…
- CVE-2022-1660CRITICALCVSS 9.8EG 9.82022-06-02
The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.
- CVE-2022-29875CRITICALCVSS 9.8EG 9.82022-06-01
A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha …
- CVE-2022-24108CRITICALCVSS 9.8EG 9.82022-05-17
The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remo…
- CVE-2022-29363CRITICALCVSS 9.8EG 9.82022-05-12
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
- CVE-2020-23621CRITICALCVSS 9.8EG 9.82022-05-02
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a …
- CVE-2020-23620CRITICALCVSS 9.8EG 9.82022-05-02
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted ser…
- CVE-2022-25767CRITICALCVSS 9.8EG 9.82022-05-01
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
- CVE-2022-29528CRITICALCVSS 9.8EG 9.82022-04-20
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
- CVE-2022-26133CRITICALCVSS 9.8EG 9.82022-04-20
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, un…
- CVE-2022-27158CRITICALCVSS 9.8EG 9.82022-04-15
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
- CVE-2022-23450CRITICALCVSS 9.8EG 9.82022-04-12
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due…
- CVE-2020-19229CRITICALCVSS 9.8EG 9.82022-04-05
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe pa…
- CVE-2021-33207CRITICALCVSS 9.8EG 9.82022-04-05
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
- CVE-2021-45899CRITICALCVSS 9.8EG 9.82022-01-28
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
- CVE-2021-43297CRITICALCVSS 9.8EG 9.82022-01-10
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessia…
- CVE-2021-42392CRITICALCVSS 9.8EG 9.82022-01-10
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote …
- CVE-2021-44029CRITICALCVSS 9.8EG 9.82021-12-22
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage…
- CVE-2021-36336CRITICALCVSS 9.8EG 9.82021-12-21
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
- CVE-2021-24857CRITICALCVSS 9.8EG 9.82021-12-13
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.
- CVE-2021-42127CRITICALCVSS 9.8EG 9.82021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
- CVE-2021-44682CRITICALCVSS 9.8EG 9.82021-12-06
An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44681CRITICALCVSS 9.8EG 9.82021-12-06
An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44680CRITICALCVSS 9.8EG 9.82021-12-06
An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44679CRITICALCVSS 9.8EG 9.82021-12-06
An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44678CRITICALCVSS 9.8EG 9.82021-12-06
An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44677CRITICALCVSS 9.8EG 9.82021-12-06
An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-36567CRITICALCVSS 9.8EG 9.82021-12-06
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
- CVE-2021-36564CRITICALCVSS 9.8EG 9.82021-12-06
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.
- CVE-2021-40865CRITICALCVSS 9.8EG 9.82021-10-25
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.…
- CVE-2021-40719CRITICALCVSS 9.8EG 9.82021-10-21
Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialized on an Adobe Connect server. An attacker can leverage this…
- CVE-2021-40720CRITICALCVSS 9.8EG 9.82021-10-15
Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this…
- CVE-2021-42090CRITICALCVSS 9.8EG 9.82021-10-07
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
- CVE-2021-41616CRITICALCVSS 9.8EG 9.82021-09-30
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjects…
- CVE-2021-31819CRITICALCVSS 9.8EG 9.82021-09-22
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
- CVE-2021-39392CRITICALCVSS 9.8EG 9.82021-09-15
The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized A…
- CVE-2021-24040CRITICALCVSS 9.8EG 9.82021-09-10
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v…
- CVE-2021-37579CRITICALCVSS 9.8EG 9.82021-09-09
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabl…
- CVE-2021-36163CRITICALCVSS 9.8EG 9.82021-09-07
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuratio…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →