CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fasterxml NetappOracle12Active Iq Unified Manager Agile PlmBanking Digital Experience+9 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). |
4Debian FasterxmlNetapp+1 more13Active Iq Unified Manager Agile PlmBanking Digital Experience+10 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). |
4Debian FasterxmlNetapp+1 more15Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+12 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms....Show more |
1Pivotal Software 1Spring Batch Jun 17, 2026 Jun 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". S...Show more |
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed....Show more |
1Phpmussel Project 1Phpmussel Jun 17, 2026 Jun 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested,...Show more |
1Inductiveautomation 1Ignition Gateway Jun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 G...Show more |
1Inductiveautomation 1Ignition Gateway Jun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Jun 5, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231. |
1Ibm 1Websphere Application Server Jun 17, 2026 Jun 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230. |
1Ibm 2Websphere Application Server Websphere Virtual EnterpriseJun 17, 2026 Jun 5, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sour...Show more |
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". |
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76. |
1Cisco 1Unified Contact Center Express Jun 17, 2026 May 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabi...Show more |
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. |
7Apache CanonicalDebian+4 more26Agile Engineering Data Management Agile PlmCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 May 20, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more |
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resu...Show more |
scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this...Show more |
pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the rea...Show more |
2Apache Oracle4Camel Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 moreJun 17, 2026 May 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |