CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Proofpoint 1Insider Threat Management Jun 17, 2026 Jan 6, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization ove...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jan 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to e...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jan 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jan 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous re...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jan 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacke...Show more |
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a s...Show more |
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrust...Show more |
2Getlaminas Zend2Laminas Http Zend FrameworkJun 17, 2026 Jan 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zen...Show more |
1Pickplugins 2Post Grid Team ShowcaseJun 17, 2026 Jan 1, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a rem...Show more |
1Pickplugins 2Post Grid Team ShowcaseJun 17, 2026 Jan 1, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely...Show more |
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP...Show more |
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used. |
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk). |
4Debian FasterxmlNetapp+1 more40Agile Plm Application Testing SuiteAutovue+37 moreJun 17, 2026 Dec 27, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org....Show more |
4Debian FasterxmlNetapp+1 more26Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+23 moreJun 17, 2026 Dec 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. |
4Debian FasterxmlNetapp+1 more25Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+22 moreJun 17, 2026 Dec 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. |
1Jsonpickle Project 1Jsonpickle Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle i...Show more |
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library. |
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that al...Show more |
Microsoft Exchange Remote Code Execution Vulnerability |