CWE-502
2,966 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,966)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide maliciou...Show more |
Visual Studio Code Remote Code Execution Vulnerability |
Microsoft Exchange Server Spoofing Vulnerability |
Microsoft Exchange Server Spoofing Vulnerability |
1Microsoft 2Sharepoint Foundation Sharepoint ServerJun 17, 2026 Jan 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft SharePoint Server Remote Code Execution Vulnerability |
2Fedoraproject Microsoft3.net FedoraPowershellJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Denial of Service Vulnerability |
A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application. |
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escal...Show more |
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service...Show more |
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation...Show more |
4Debian FasterxmlNetapp+1 more5Active Iq Unified Manager Debian LinuxJackson Databind+2 moreJun 17, 2026 Dec 26, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLook...Show more |
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components. |
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework. |
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object. |
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php. |
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). |
1Activerecord Project 1Activerecord Jun 17, 2026 Dec 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (vi...Show more |
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE:...Show more |
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml...Show more |
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands. |