CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 1Sppa T3000 Application Server Jun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifica...Show more |
1Siemens 1Sppa T3000 Application Server Jun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote cod...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxLeapJun 17, 2026 Dec 12, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and c...Show more |
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a pac...Show more |
1Telerik 1Ui For Asp.net Ajax Jun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-201...Show more |
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code. |
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class,...Show more |
1Dell 1Emc Storage Monitoring And Reporting Jun 17, 2026 Nov 26, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a craft...Show more |
1Cisco 4Rv016 Multi Wan Vpn Firmware Rv042 Dual Wan Vpn FirmwareRv042g Dual Gigabit Wan Vpn Firmware+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must...Show more |
IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an...Show more |
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. |
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute...Show more |
1Centrify 2Authentication Service Privilege Elevation ServiceJun 17, 2026 Nov 5, 2019 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during...Show more |
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. |
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debu...Show more |
A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacker can use the 'class' property of the JSO...Show more |
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections |
5Debian FasterxmlNetapp+2 more22Banking Platform Communications Billing And Revenue ManagementCommunications Calendar Server+19 moreJun 17, 2026 Oct 12, 2019 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the se...Show more |
5Debian FasterxmlNetapp+2 more12Active Iq Unified Manager Customer Management And Segmentation FoundationDebian Linux+9 moreJun 17, 2026 Oct 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup. |
1Redis Wrapper Project 1Redis Wrapper Jun 17, 2026 Oct 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts. |