CWE-502
3,211 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,211)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution |
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution |
In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics. |
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. Th...Show more |
Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3. |
Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3. |
Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <= 3.0.0. |
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects Amwerk: from n/a through <= 1.2.0. |
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects WP Optimize By xTraffic: from n/a through <= 5.1.6. |
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulner...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Jun 25, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. |
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server. |
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnera...Show more |
PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in the read method of the SparseMatrix class that can lead to a wide rang...Show more |
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation l...Show more |
1Trendmicro 1Trend Micro Endpoint Encryption Jun 17, 2026 Jun 17, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE...Show more |
1Trendmicro 1Trend Micro Endpoint Encryption Jun 17, 2026 Jun 17, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain...Show more |
1Trendmicro 1Trend Micro Endpoint Encryption Jun 17, 2026 Jun 17, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE...Show more |
1Trendmicro 1Trend Micro Endpoint Encryption Jun 17, 2026 Jun 17, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE...Show more |
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-...Show more |