← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Application Server
Jun 17, 2026
Jul 17, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.Show less
1Apache
1Airflow
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the...Show more
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.Show less
2Iconics
Mitsubishielectric
11Bizviz
Energy AnalytixFacility Analytix+8 more
Jun 17, 2026
Jul 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208...Show more
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.Show less
2Iconics
Mitsubishielectric
11Bizviz
Energy AnalytixFacility Analytix+8 more
Jun 17, 2026
Jul 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC...Show more
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.Show less
2Iconics
Mitsubishielectric
11Bizviz
Energy AnalytixFacility Analytix+8 more
Jun 17, 2026
Jul 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208...Show more
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.Show less
1Mit
1Scratch Vm
Jun 17, 2026
Jul 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code execution because the URL's c...Show more
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code execution because the URL's content is treated as a script and is executed as a worker. The responsible code is getExtensionIdForOpcode in serialization/sb3.js. The use of _ is incompatible with a protection mechanism in older versions, in which URLs were split and consequently deserialization attacks were prevented. NOTE: the scratch.mit.edu hosted service is not affected because of the lack of worker scripts.Show less
1Apache
1Ofbiz
Jun 17, 2026
Jul 15, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
1Microsoft
3Sharepoint Enterprise Server
Sharepoint FoundationSharepoint Server
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution V...Show more
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.Show less
1Apache
1Dubbo
Jun 17, 2026
Jul 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicio...Show more
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.Show less
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Jun 17, 2026
Jul 9, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially c...Show more
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176677.Show less
1Atlassian
2Jira
Jira Software Data Center
Jun 17, 2026
Jul 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server an...Show more
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if they were able to exploit a server side template injection vulnerability. The affected versions are before version 7.13.0, from version 8.0.0 before 8.5.0, and from version 8.6.0 before version 8.8.1.Show less
1Jenkins
1Kubernetes Ci
Jun 17, 2026
Jul 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
1Beakerbrowser
1Beaker
Nov 21, 2024
Jun 26, 2020
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
1Redhat
1Wildfly
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly...Show more
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.Show less
1Tendenci
1Tendenci
Jun 17, 2026
Jun 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.
1Squirrelmail
1Squirrelmail
Jun 17, 2026
Jun 20, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not sa...Show more
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant classes must be declared before unserialize is called (or must be autoloaded).Show less
1Squirrelmail
1Squirrelmail
Jun 17, 2026
Jun 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php.
3Debian
OpensuseRubyonrails
3Debian Linux
LeapRails
Jun 17, 2026
Jun 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.Show less
3Debian
OpensuseRubyonrails
4Backports Sle
Debian LinuxLeap+1 more
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
4Debian
FasterxmlNetapp+1 more
14Active Iq Unified Manager
Agile PlmBanking Digital Experience+11 more
Jun 17, 2026
Jun 16, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).