CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vul...Show more |
1Qualcomm 10Ar8035 Firmware Qca8081 FirmwareQca8337 Firmware+7 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile |
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that...Show more |
2Alibaba Oracle2Communications Cloud Native Core Unified Data Repository FastjsonJun 17, 2026 Jun 10, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vuln...Show more |
1Keysight 2N6841a Rf Firmware N6854a FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code. |
1Siemens 18Biograph Horizon Pet/ct Systems Firmware Magnetom Numaris X FirmwareMammomat Revelation Firmware+15 moreJun 17, 2026 Jun 1, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC2...Show more |
1Cognex 1In Sight Opc Server Jun 17, 2026 May 23, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalat...Show more |
2Netapp Yaml Project2Astra Trident YamlJun 17, 2026 May 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. |
1Rockwellautomation 3Connected Component Workbench Isagraf WorkbenchSafety Instrumented Systems WorkstationJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be des...Show more |
The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause Do...Show more |
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a...Show more |
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files. |
1Booking Calendar Project 1Booking Calendar Jun 17, 2026 May 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above t...Show more |
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class. |
1Squire Technologies 1Svi Ms Management System Jun 17, 2026 May 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute ar...Show more |
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary cod...Show more |
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. |
4Debian GoogleNetapp+1 more6Active Iq Unified Manager Debian LinuxFinancial Services Crime And Compliance Management Studio+3 moreJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation produ...Show more |
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. |