← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Sharepoint Enterprise Server
Sharepoint FoundationSharepoint Server
Jun 17, 2026
Feb 25, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Microsoft SharePoint Remote Code Execution Vulnerability
1Kollectapp
1Kollect
Jun 17, 2026
Feb 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.
1Hr Portal Project
1Hr Portal
Jun 17, 2026
Feb 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
1Microsoft
1Qlib
Jun 17, 2026
Feb 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
1Pystemon Project
1Pystemon
Jun 17, 2026
Feb 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.
1Qognify
1Ocularis
Jun 17, 2026
Feb 12, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific flaw exists within...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of serialized objects provided to the EventCoordinator endpoint. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-11257.Show less
1Netmotionsoftware
1Netmotion Mobility
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
1Netmotionsoftware
1Netmotion Mobility
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
1Netmotionsoftware
1Netmotion Mobility
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
1Netmotionsoftware
1Netmotion Mobility
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
1Solarwinds
1Orion Platform
Jun 17, 2026
Feb 3, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to T...Show more
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Feb 3, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
1Aca
1Assuweb
Jun 17, 2026
Jan 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP re...Show more
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jan 28, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deseria...Show more
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 190912.Show less
1Ibm
3Mq
Mq ApplianceWebsphere Mq
Jun 17, 2026
Jan 28, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to e...Show more
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that...Show more
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Apache
1Java Chassis
Jun 17, 2026
Jan 25, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache...Show more
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5Show less
4Emerson
Pepperl FuchsWago+1 more
7Dtminspector 3
Fdtcontainer ApplicationFdtcontainer Component+4 more
Jun 17, 2026
Jan 22, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
5Apache
DebianFasterxml+2 more
10Active Iq Unified Manager
Commerce Experience ManagerCommerce Guided Search+7 more
Jul 24, 2026
Jan 19, 2021
N/A· v4
8.1 HIGH· v3
8.3 HIGH· v2
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as...Show more
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Opencats
1Opencats
Jun 17, 2026
Jan 18, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter...Show more
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object injection exploit chain can leverage an __destruct magic method in guzzlehttp.Show less