← Back
CWE-502

3,199 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,199)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Afterlogic
1Aurora Files
Jul 9, 2026
Oct 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
1Deyue Remote Vehicle Management System Project
1Deyue Remote Vehicle Management System
Jun 17, 2026
Oct 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.
1Apache
1Avro
Jun 17, 2026
Sep 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apach...Show more
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.Show less
1Consensys
1Gnark Crypto
Jun 17, 2026
Sep 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
1Illumio
1Core Policy Compute Engine
Jun 17, 2026
Sep 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network...Show more
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.   Show less
1Emlog
1Emlog
Jun 17, 2026
Sep 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
1Progress
1Ws Ftp Server
Jun 17, 2026
Sep 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Serve...Show more
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.Show less
1Phppgadmin Project
1Phppgadmin
Jun 17, 2026
Sep 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple pla...Show more
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized.Show less
1Ssssssss
1Spider Flow
Jun 17, 2026
Sep 17, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.getConnection of the file src/main/java/org/spiderflow/controller/DataS...Show more
A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.getConnection of the file src/main/java/org/spiderflow/controller/DataSourceController.java of the component API. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239857 was assigned to this vulnerability.Show less
1Gnome
1Glib
Jun 17, 2026
Sep 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.
1Gnome
1Glib
Jun 17, 2026
Sep 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very sl...Show more
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.Show less
1Adobe
1Coldfusion
Jun 17, 2026
Sep 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation...Show more
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.Show less
1Microsoft
1Azure Devops Server
Jun 17, 2026
Sep 12, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Azure DevOps Server Remote Code Execution Vulnerability
1Microsoft
1Exchange Server
Jun 17, 2026
Sep 12, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Microsoft Exchange Server Information Disclosure Vulnerability
1Microsoft
1Exchange Server
Jun 17, 2026
Sep 12, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft Exchange Server Spoofing Vulnerability
1Microsoft
1Exchange Server
Jun 17, 2026
Sep 12, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft Exchange Server Remote Code Execution Vulnerability
1Microsoft
1Exchange Server
Jun 17, 2026
Sep 12, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft Exchange Server Remote Code Execution Vulnerability
1Microsoft
1Exchange Server
Jun 17, 2026
Sep 12, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft Exchange Server Remote Code Execution Vulnerability
1Microsoft
1Identity Linux Broker
Jun 17, 2026
Sep 12, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Microsoft Identity Linux Broker Remote Code Execution Vulnerability
1Google
1Android
Jun 17, 2026
Sep 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additi...Show more
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less