CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without auth...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilit...Show more |
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors. |
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain. |
1Databaseschemareader Project 1Dbschemareader Jun 17, 2026 Nov 4, 2020 N/A· v4 8.0 HIGH· v3 6.8 MEDIUM· v2 DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `....Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Nov 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. |
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow...Show more |
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication |
3Arcinfo ArcinformatiquePcvuesolutions3Pcvue PcvuePcvueJul 9, 2026 Oct 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server. |
MyBatis before 3.5.6 mishandles deserialization of object streams. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Oct 8, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malici...Show more |
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicious .NET serialized files, an attacker can...Show more |
SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerabili...Show more |
3Debian FasterxmlOracle26Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+23 moreJun 17, 2026 Sep 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. |
1Schneider Electric 1Scadapack X70 Security Administrator Jun 17, 2026 Sep 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing...Show more |
1Schneider Electric 1Scadapack 7x Remote Connect Jun 17, 2026 Sep 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a ma...Show more |
1Fluffycogs Project 1Fluffycogs Jun 17, 2026 Sep 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Discord users can use specially crafted messages to perform destructive actions and/or access sensitive...Show more |