CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in...Show more |
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to co...Show more |
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successfu...Show more |
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution. |
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerabili...Show more |
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. |
1Microsoft 10Windows 10 1607 Windows 10 1809Windows 10 21h2+7 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) bin...Show more |
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. |
1Microsoft 5Sql Server 2016 Sql Server 2017Sql Server 2019+2 moreAug 20, 2026 Jul 14, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
1Microsoft 5Sql Server 2016 Sql Server 2017Sql Server 2019+2 moreAug 20, 2026 Jul 14, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriente...Show more |
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization...Show more |
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. |
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. |