CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 21 of 70
- CVE-2021-34066CRITICALCVSS 9.8EG 9.82021-08-30
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.
- CVE-2021-21741CRITICALCVSS 9.8EG 9.82021-08-30
There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization comman…
- CVE-2021-37544CRITICALCVSS 9.8EG 9.82021-08-06
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
- CVE-2021-34371CRITICALCVSS 9.8EG 9.82021-08-05
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies w…
- CVE-2021-29781CRITICALCVSS 9.8EG 9.82021-07-30
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute …
- CVE-2021-37578CRITICALCVSS 9.8EG 9.82021-07-29
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass param…
- CVE-2020-5341CRITICALCVSS 9.8EG 9.82021-07-28
Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 and 2.4.1 contain a Deserialization…
- CVE-2021-24384CRITICALCVSS 9.8EG 9.82021-07-06
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issu…
- CVE-2021-35971CRITICALCVSS 9.8EG 9.82021-06-30
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.
- CVE-2021-31649CRITICALCVSS 9.8EG 9.82021-06-24
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- CVE-2020-9493CRITICALCVSS 9.8EG 9.82021-06-16
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
- CVE-2021-33806CRITICALCVSS 9.8EG 9.82021-06-03
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.
- CVE-2021-30179CRITICALCVSS 9.8EG 9.82021-06-01
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first a…
- CVE-2021-25641CRITICALCVSS 9.8EG 9.82021-06-01
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by ta…
- CVE-2021-33790CRITICALCVSS 9.8EG 9.82021-05-31
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the…
- CVE-2021-32075CRITICALCVSS 9.8EG 9.82021-05-24
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
- CVE-2021-31474CRITICALCVSS 9.8EG 9.82021-05-21
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists withi…
- CVE-2021-33026CRITICALCVSS 9.8EG 9.82021-05-13
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redi…
- CVE-2021-32098CRITICALCVSS 9.8EG 9.82021-05-07
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
- CVE-2020-36326CRITICALCVSS 9.8EG 9.82021-04-28
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames…
- CVE-2021-29476CRITICALCVSS 9.8EG 9.82021-04-27
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
- CVE-2021-30128CRITICALCVSS 9.8EG 9.82021-04-27
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
- CVE-2021-29200CRITICALCVSS 9.8EG 9.82021-04-27
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
- CVE-2021-3287CRITICALCVSS 9.8EG 9.82021-04-22
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
- CVE-2021-21426CRITICALCVSS 9.8EG 9.82021-04-21
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in ver…
- CVE-2021-27850CRITICALCVSS 9.8EG 9.82021-04-15
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-201…
- CVE-2021-21524CRITICALCVSS 9.8EG 9.82021-04-12
Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to arbitrary privileged cod…
- CVE-2021-21350CRITICALCVSS 9.8EG 9.82021-03-23
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. N…
- CVE-2021-21347CRITICALCVSS 9.8EG 9.82021-03-23
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating t…
- CVE-2021-21346CRITICALCVSS 9.8EG 9.82021-03-23
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating t…
- CVE-2021-21344CRITICALCVSS 9.8EG 9.82021-03-23
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating t…
- CVE-2021-26295CRITICALCVSS 9.8EG 9.82021-03-22
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
- CVE-2020-36282CRITICALCVSS 9.8EG 9.82021-03-12
JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.
- CVE-2020-29045CRITICALCVSS 9.8EG 9.82021-03-11
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
- CVE-2020-24914CRITICALCVSS 9.8EG 9.82021-03-04
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
- CVE-2020-29047CRITICALCVSS 9.8EG 9.82021-03-03
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
- CVE-2021-27335CRITICALCVSS 9.8EG 9.82021-02-18
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.
- CVE-2021-22855CRITICALCVSS 9.8EG 9.82021-02-17
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
- CVE-2021-27213CRITICALCVSS 9.8EG 9.82021-02-14
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.
- CVE-2020-27868CRITICALCVSS 9.8EG 9.82021-02-12
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of ser…
- CVE-2021-25274CRITICALCVSS 9.8EG 9.82021-02-03
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that t…
- CVE-2021-3160CRITICALCVSS 9.8EG 9.82021-01-28
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in…
- CVE-2020-4682CRITICALCVSS 9.8EG 9.82021-01-28
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary co…
- CVE-2020-27583CRITICALCVSS 9.8EG 9.82021-01-26
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that are no longer supp…
- CVE-2021-25294CRITICALCVSS 9.8EG 9.82021-01-18
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object in…
- CVE-2020-24639CRITICALCVSS 9.8EG 9.82021-01-15
There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the und…
- CVE-2020-23653CRITICALCVSS 9.8EG 9.82021-01-13
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.
- CVE-2020-11995CRITICALCVSS 9.8EG 9.82021-01-11
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protool, during Hessian2 deserializin…
- CVE-2020-10658CRITICALCVSS 9.8EG 9.82021-01-06
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to execute arbitrary co…
- CVE-2020-10656CRITICALCVSS 9.8EG 9.82021-01-06
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to ex…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →