← Back
CWE-502

3,199 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,199)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 12, 2024
8.4 HIGH· v4
N/A· v3
N/A· v2
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functio...Show more
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.Show less
1Aveva
1Pi Asset Framework Client
Jun 17, 2026
Jun 12, 2024
7.0 HIGH· v4
7.8 HIGH· v3
N/A· v2
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to imp...Show more
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.Show less
1Dell
1Common Event Enabler
Jun 17, 2026
Jun 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary c...Show more
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.Show less
1Microsoft
1Dynamics 365 Business Central
Aug 10, 2026
Jun 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
1Nukeviet
2Egovernment
Nukeviet
Jun 17, 2026
Jun 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
1Summar
1Mentor
Jun 17, 2026
Jun 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload i...Show more
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.Show less
1Bdthemes
1Element Pack
Jun 17, 2026
Jun 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Elem...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a before 7.19.3.Show less
-
-
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
-
-
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.
-
-
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted w...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system w...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when intera...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system wh...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted wi...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interac...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.Show less
1Lfprojects
1Mlflow
Jun 17, 2026
Jun 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interac...Show more
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.Show less
-
-
Jun 17, 2026
May 30, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.