CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems. |
1Ptc 2Flexplm Windchill PdmlinkJun 30, 2026 Jun 18, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also a...Show more |
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP reques...Show more |
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malici...Show more |
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects...Show more |
Unauthenticated PHP Object Injection in Moderno < 1.43 versions. |
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. |
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. |
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. |
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. |
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. |
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. |
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. |
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. |
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. |
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. |
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. |
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. |
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. |
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection.
This issue affects Creatify: from n/a through 1.5. |