CWE-502
2,966 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,966)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a...Show more |
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files. |
1Booking Calendar Project 1Booking Calendar Jun 17, 2026 May 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above t...Show more |
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class. |
1Squire Technologies 1Svi Ms Management System Jun 17, 2026 May 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute ar...Show more |
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary cod...Show more |
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. |
4Debian GoogleNetapp+1 more6Active Iq Unified Manager Debian LinuxFinancial Services Crime And Compliance Management Studio+3 moreJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation produ...Show more |
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. |
1Atlassian 1Bitbucket Data Center Jun 17, 2026 Apr 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0...Show more |
1Oracle 1Application Development Framework Jun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vul...Show more |
pearweb < 1.32 suffers from Deserialization of Untrusted Data. |
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code...Show more |
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a ma...Show more |
1Vmware 5Cloud Foundation Identity ManagerVrealize Automation+2 moreJun 17, 2026 Apr 13, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserial...Show more |
1Vmware 5Cloud Foundation Identity ManagerVrealize Automation+2 moreJun 17, 2026 Apr 13, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserial...Show more |
1Schneider Electric 1Software Update Jun 17, 2026 Apr 13, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated fo...Show more |
1Siemens 2Simatic Energy Manager Basic Simatic Energy Manager ProJun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously c...Show more |
A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code. This vulnerability is due to improper deserialization of Java cod...Show more |