CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 23 of 70
- CVE-2020-9547CRITICALCVSS 9.8EG 9.82020-03-02
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
- CVE-2020-9546CRITICALCVSS 9.8EG 9.82020-03-02
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
- CVE-2020-8441CRITICALCVSS 9.8EG 9.82020-02-19
JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.
- CVE-2019-20477CRITICALCVSS 9.8EG 9.82020-02-19
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for C…
- CVE-2020-9006CRITICALCVSS 9.8EG 9.82020-02-17
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. Thi…
- CVE-2020-8840CRITICALCVSS 9.8EG 9.82020-02-10
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
- CVE-2013-4521CRITICALCVSS 9.8EG 9.82020-02-06
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serializ…
- CVE-2020-3716CRITICALCVSS 9.8EG 9.82020-01-29
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2019-17570CRITICALCVSS 9.8EG 9.82020-01-23
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrar…
- CVE-2020-6959CRITICALCVSS 9.8EG 9.82020-01-22
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAX…
- CVE-2019-17076CRITICALCVSS 9.8EG 9.82020-01-08
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro s…
- CVE-2014-1860CRITICALCVSS 9.8EG 9.82020-01-08
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
- CVE-2019-20330CRITICALCVSS 9.8EG 9.82020-01-03
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
- CVE-2016-1000027CRITICALCVSS 9.8EG 9.82020-01-02
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occu…
- CVE-2019-17571CRITICALCVSS 9.8EG 9.82019-12-20
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network…
- CVE-2019-8662CRITICALCVSS 9.8EG 9.82019-12-18
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
- CVE-2019-18956CRITICALCVSS 9.8EG 9.82019-12-17
Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution…
- CVE-2019-19826CRITICALCVSS 9.8EG 9.82019-12-16
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_…
- CVE-2014-3699CRITICALCVSS 9.8EG 9.82019-12-15
eDeploy has RCE via cPickle deserialization of untrusted data
- CVE-2019-18316CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets…
- CVE-2019-18283CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by send…
- CVE-2019-19230CRITICALCVSS 9.8EG 9.82019-12-09
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
- CVE-2019-17556CRITICALCVSS 9.8EG 9.82019-12-04
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result …
- CVE-2019-1373CRITICALCVSS 9.8EG 9.82019-11-12
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
- CVE-2019-18364CRITICALCVSS 9.8EG 9.82019-10-31
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
- CVE-2019-12017CRITICALCVSS 9.8EG 9.82019-10-24
A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacker can use the 'class' property of the JSON request sent to t…
- CVE-2019-13116CRITICALCVSS 9.8EG 9.82019-10-16
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
- CVE-2019-17531CRITICALCVSS 9.8EG 9.82019-10-12
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apach…
- CVE-2019-17267CRITICALCVSS 9.8EG 9.82019-10-07
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
- CVE-2019-17206CRITICALCVSS 9.8EG 9.82019-10-05
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
- CVE-2019-16891CRITICALCVSS 9.8EG 9.82019-10-04
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
- CVE-2019-12630CRITICALCVSS 9.8EG 9.82019-10-02
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization o…
- CVE-2019-16943CRITICALCVSS 9.8EG 9.82019-10-01
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy…
- CVE-2019-16942CRITICALCVSS 9.8EG 9.82019-10-01
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commo…
- CVE-2019-10202CRITICALCVSS 9.8EG 9.82019-10-01
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported …
- CVE-2019-9365CRITICALCVSS 9.8EG 9.82019-09-27
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: An…
- CVE-2019-16894CRITICALCVSS 9.8EG 9.82019-09-26
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
- CVE-2019-16755CRITICALCVSS 9.8EG 9.82019-09-26
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted applica…
- CVE-2019-0195CRITICALCVSS 9.8EG 9.82019-09-16
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most prob…
- CVE-2019-16335CRITICALCVSS 9.8EG 9.82019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
- CVE-2019-14540CRITICALCVSS 9.8EG 9.82019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
- CVE-2019-0189CRITICALCVSS 9.8EG 9.82019-09-11
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the r…
- CVE-2017-18605CRITICALCVSS 9.8EG 9.82019-09-10
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
- CVE-2018-11569CRITICALCVSS 9.8EG 9.82019-09-05
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.
- CVE-2019-15780CRITICALCVSS 9.8EG 9.82019-08-29
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
- CVE-2019-15521CRITICALCVSS 9.8EG 9.82019-08-26
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
- CVE-2018-20987CRITICALCVSS 9.8EG 9.82019-08-22
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
- CVE-2019-11030CRITICALCVSS 9.8EG 9.82019-08-22
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collect…
- CVE-2019-15321CRITICALCVSS 9.8EG 9.82019-08-22
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
- CVE-2019-15320CRITICALCVSS 9.8EG 9.82019-08-22
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →