CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 24 of 70
- CVE-2019-15319CRITICALCVSS 9.8EG 9.82019-08-22
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
- CVE-2018-20984CRITICALCVSS 9.8EG 9.82019-08-22
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
- CVE-2018-11779CRITICALCVSS 9.8EG 9.82019-07-26
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
- CVE-2019-10173CRITICALCVSS 9.8EG 9.82019-07-23
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when…
- CVE-2019-1010306CRITICALCVSS 9.8EG 9.82019-07-15
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector…
- CVE-2018-11307CRITICALCVSS 9.8EG 9.82019-07-09
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
- CVE-2019-11011CRITICALCVSS 9.8EG 9.82019-06-21
Akamai CloudTest before 58.30 allows remote code execution.
- CVE-2018-15890CRITICALCVSS 9.8EG 9.82019-06-20
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the…
- CVE-2019-7840CRITICALCVSS 9.8EG 9.82019-06-12
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2019-11945CRITICALCVSS 9.8EG 9.82019-06-05
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- CVE-2019-11944CRITICALCVSS 9.8EG 9.82019-06-05
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- CVE-2019-10069CRITICALCVSS 9.8EG 9.82019-05-31
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
- CVE-2019-6980CRITICALCVSS 9.8EG 9.82019-05-29
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
- CVE-2019-7091CRITICALCVSS 9.8EG 9.82019-05-24
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2019-12241CRITICALCVSS 9.8EG 9.82019-05-20
The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
- CVE-2019-12240CRITICALCVSS 9.8EG 9.82019-05-20
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.
- CVE-2019-4279CRITICALCVSS 9.8EG 9.82019-05-17
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
- CVE-2019-11831CRITICALCVSS 9.8EG 9.82019-05-09
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a pha…
- CVE-2019-11830CRITICALCVSS 9.8EG 9.82019-05-09
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
- CVE-2019-5434CRITICALCVSS 9.8EG 9.82019-05-06
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of…
- CVE-2019-7214CRITICALCVSS 9.8EG 9.82019-04-24
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default…
- CVE-2017-18365CRITICALCVSS 9.8EG 9.82019-03-28
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and ca…
- CVE-2018-19276CRITICALCVSS 9.8EG 9.82019-03-21
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
- CVE-2019-0192CRITICALCVSS 9.8EG 9.82019-03-07
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserializat…
- CVE-2019-0187CRITICALCVSS 9.8EG 9.82019-03-06
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data de…
- CVE-2019-9212CRITICALCVSS 9.8EG 9.82019-02-27
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, r…
- CVE-2019-7743CRITICALCVSS 9.8EG 9.82019-02-12
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler …
- CVE-2019-6503CRITICALCVSS 9.8EG 9.82019-01-22
There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave met…
- CVE-2018-20732CRITICALCVSS 9.8EG 9.82019-01-17
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
- CVE-2019-6446CRITICALCVSS 9.8EG 9.82019-01-16
An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties d…
- CVE-2018-20718CRITICALCVSS 9.8EG 9.82019-01-15
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged us…
- CVE-2018-19362CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
- CVE-2018-19361CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
- CVE-2018-19360CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
- CVE-2018-14720CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
- CVE-2018-14719CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
- CVE-2018-14718CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
- CVE-2018-6331CRITICALCVSS 9.8EG 9.82018-12-31
Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.
- CVE-2018-1000833CRITICALCVSS 9.8EG 9.82018-12-20
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
- CVE-2018-1000832CRITICALCVSS 9.8EG 9.82018-12-20
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
- CVE-2018-1000827CRITICALCVSS 9.8EG 9.82018-12-20
Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
- CVE-2018-1000824CRITICALCVSS 9.8EG 9.82018-12-20
MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
- CVE-2018-20148CRITICALCVSS 9.8EG 9.82018-12-14
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_a…
- CVE-2018-15381CRITICALCVSS 9.8EG 9.82018-11-08
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserializatio…
- CVE-2018-8021CRITICALCVSS 9.8EG 9.82018-11-07
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Fo…
- CVE-2018-18628CRITICALCVSS 9.8EG 9.82018-10-23
An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a maliciou…
- CVE-2018-3245CRITICALCVSS 9.8EG 9.82018-10-17
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauth…
- CVE-2018-18240CRITICALCVSS 9.8EG 9.82018-10-11
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
- CVE-2018-3972CRITICALCVSS 9.8EG 9.82018-09-26
An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet …
- CVE-2018-15965CRITICALCVSS 9.8EG 9.82018-09-25
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →