CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 3 of 63
- CVE-2017-17672CRITICALCVSS 9.8EG 9.82017-12-14
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Temp…
- CVE-2017-18342CRITICALCVSS 9.8EG 9.82018-06-27
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the funct…
- CVE-2017-18365CRITICALCVSS 9.8EG 9.82019-03-28
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and ca…
- CVE-2017-18375HIGHCVSS 8.8EG 8.82019-05-24
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
- CVE-2017-18604HIGHCVSS 7.5EG 7.52019-09-10
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
- CVE-2017-18605CRITICALCVSS 9.8EG 9.82019-09-10
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
- CVE-2017-20189CRITICALCVSS 9.8EG 9.82024-01-22
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.
- CVE-2017-20206CRITICALCVSS 9.8EG 9.82025-10-18
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inj…
- CVE-2017-20207CRITICALCVSS 9.8EG 9.82025-10-18
The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP…
- CVE-2017-20208CRITICALCVSS 9.8EG 9.82025-10-18
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input fro…
- CVE-2017-2292CRITICALCVSS 9.0EG 9.02017-06-30
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested i…
- CVE-2017-2295HIGHCVSS 8.2EG 8.22017-07-05
Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to …
- CVE-2017-2608HIGHCVSS 8.8EG 8.82018-05-15
Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (SECURITY-383).
- CVE-2017-3066CRITICALCVSS 9.8EG 9.8⚠ KEV2017-04-27
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary c…
- CVE-2017-3159CRITICALCVSS 9.8EG 9.82017-03-07
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
- CVE-2017-3199HIGHCVSS 8.1EG 8.12018-06-11
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the a…
- CVE-2017-3200HIGHCVSS 8.1EG 8.12018-06-11
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The abili…
- CVE-2017-3201HIGHCVSS 8.1EG 8.12018-06-11
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. …
- CVE-2017-3202CRITICALCVSS 9.8EG 9.82018-06-11
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans set…
- CVE-2017-3203HIGHCVSS 8.1EG 8.12018-06-11
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the …
- CVE-2017-3207CRITICALCVSS 9.8EG 9.82018-06-11
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A…
- CVE-2017-4914CRITICALCVSS 9.8EG 9.82017-06-07
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
- CVE-2017-4947CRITICALCVSS 9.8EG 9.82018-01-29
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on th…
- CVE-2017-4995HIGHCVSS 8.1EG 8.12017-11-27
An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary …
- CVE-2017-5641CRITICALCVSS 9.8EG 9.82017-12-28
Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undes…
- CVE-2017-5645CRITICALCVSS 9.8EG 9.82017-04-17
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrar…
- CVE-2017-5790CRITICALCVSS 9.8EG 9.82018-02-15
A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.
- CVE-2017-5792CRITICALCVSS 9.8EG 9.82018-02-15
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-5830CRITICALCVSS 9.8EG 9.82017-03-03
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
- CVE-2017-5878CRITICALCVSS 9.8EG 9.82017-06-08
The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data.
- CVE-2017-5929CRITICALCVSS 9.8EG 9.82017-03-13
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
- CVE-2017-5941CRITICALCVSS 9.8EG 9.82017-02-09
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked …
- CVE-2017-5954CRITICALCVSS 9.8EG 9.82017-02-10
An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked…
- CVE-2017-5983CRITICALCVSS 9.8EG 9.82017-04-10
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a craft…
- CVE-2017-7293HIGHCVSS 7.8EG 7.82017-04-26
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.…
- CVE-2017-7504CRITICALCVSS 9.8EG 9.82017-05-19
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, whi…
- CVE-2017-7525CRITICALCVSS 9.8EG 9.82018-02-06
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method…
- CVE-2017-8045CRITICALCVSS 9.8EG 9.82017-11-27
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a …
- CVE-2017-8804HIGHCVSS 7.5EG 7.52017-05-07
The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumptio…
- CVE-2017-8829HIGHCVSS 7.8EG 7.82017-05-08
Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.
- CVE-2017-8962HIGHCVSS 8.8EG 8.82018-02-15
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-8963HIGHCVSS 8.8EG 8.82018-02-15
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-8964HIGHCVSS 8.8EG 8.82018-02-15
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-8965HIGHCVSS 8.8EG 8.82018-02-15
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-8966HIGHCVSS 8.8EG 8.82018-02-15
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-8967HIGHCVSS 8.8EG 8.82018-02-15
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-9363CRITICALCVSS 9.8EG 9.82017-06-02
Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.
- CVE-2017-9424CRITICALCVSS 9.8EG 9.82017-06-22
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
- CVE-2017-9785CRITICALCVSS 9.8EG 9.82017-07-20
Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.
- CVE-2017-9805CRITICALCVSS 8.1EG 9.0⚠ KEV2017-09-15
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when dese…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →