CWE-502
2,966 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,966)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication...Show more |
3Debian NetappOracle197 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+16 moreJun 17, 2026 Jan 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle...Show more |
3Apache OracleQos26Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+23 moreJun 17, 2026 Jan 18, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. |
5Apache BroadcomNetapp+2 more26Advanced Supply Chain Planning Brocade SannavBusiness Intelligence+23 moreJun 17, 2026 Jan 18, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has ac...Show more |
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document. |
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization prot...Show more |
3Debian H2databaseOracle3Communications Cloud Native Core Policy Debian LinuxH2Jun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI serve...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditio...Show more |
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulne...Show more |
1Redhat 1Jboss Enterprise Application Platform Jun 17, 2026 Dec 23, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage. |
1Lightningai 1Pytorch Lightning Jun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 pytorch-lightning is vulnerable to Deserialization of Untrusted Data |
1Ajax.net Professional Project 1Ajax.net Professional Jun 17, 2026 Dec 22, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leverage...Show more |
1Quest 1Kace Desktop Authority Jun 17, 2026 Dec 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An at...Show more |
1Dell 1Wyse Management Suite Jun 17, 2026 Dec 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system. |
4Netapp QosRedhat+1 more6Cloud Manager LogbackSatellite+3 moreJun 17, 2026 Dec 16, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User i...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain. |
12Apache AppleBentley+9 more1436bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+140 moreJun 17, 2026 Dec 10, 2021 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other J...Show more |
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution. |