CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Feb 25, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Remote Code Execution Vulnerability |
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter. |
1Hr Portal Project 1Hr Portal Jun 17, 2026 Feb 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands. |
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. |
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific flaw exists within...Show more |
1Netmotionsoftware 1Netmotion Mobility Jun 17, 2026 Feb 8, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet. |
1Netmotionsoftware 1Netmotion Mobility Jun 17, 2026 Feb 8, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject. |
1Netmotionsoftware 1Netmotion Mobility Jun 17, 2026 Feb 8, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet. |
1Netmotionsoftware 1Netmotion Mobility Jun 17, 2026 Feb 8, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet. |
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to T...Show more |
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution. |
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP re...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jan 28, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deseria...Show more |
1Ibm 3Mq Mq ApplianceWebsphere MqJun 17, 2026 Jan 28, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to e...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Jan 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that...Show more |
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache...Show more |
4Emerson Pepperl FuchsWago+1 more7Dtminspector 3 Fdtcontainer ApplicationFdtcontainer Component+4 moreJun 17, 2026 Jan 22, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. |
5Apache DebianFasterxml+2 more10Active Iq Unified Manager Commerce Experience ManagerCommerce Guided Search+7 moreJul 24, 2026 Jan 19, 2021 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as...Show more |
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter...Show more |