← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
-
-
Jun 17, 2026
Jun 15, 2026
7.5 HIGH· v4
N/A· v3
N/A· v2
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Becau...Show more
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads can trigger dangerous magic methods (e.g., __wakeup() and __destruct()) and leverage gadget chains, resulting in arbitrary code execution. Exploitation is triggered automatically when an administrator accesses the admin panel. When successfully exploited, this vulnerability allows attackers to execute arbitrary code on the server via manipulated serialized data transmitted over an unprotected channel. This issue was mitigated by limiting the communication to HTTPS in a patch for version 6.8 published on 14.05.2026, deployments without this patch remain vulnerable.Show less
-
-
Jun 17, 2026
Jun 14, 2026
7.1 HIGH· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserializ...Show more
A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Apache
1Cxf
Jul 15, 2026
Jun 12, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activa...Show more
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.Show less
1Apache
1Cxf
Jul 15, 2026
Jun 12, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowe...Show more
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.Show less
1Vmware
1Spring For Graphql
Jul 17, 2026
Jun 11, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the applic...Show more
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.Show less
1Splunk
3Splunk
Splunk Cloud PlatformSplunk Secure Gateway
Jun 17, 2026
Jun 10, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3....Show more
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.Show less
1Jenkins
1Jenkins
Jul 15, 2026
Jun 10, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a...Show more
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.Show less
1Nsa
1Ghidra
Jul 14, 2026
Jun 10, 2026
8.6 HIGH· v4
8.8 HIGH· v3
N/A· v2
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a...Show more
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands.Show less
-
-
Jun 17, 2026
Jun 10, 2026
8.4 HIGH· v4
N/A· v3
N/A· v2
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a...Show more
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 for reporting.Show less