CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2. |
1Strategy11 1Formidable Form Builder Jun 17, 2026 Aug 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. |
2Fork Cms Spoon Library2Fork Cms Spoon LibraryJun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object. |
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. |
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the ....Show more |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. |
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. |
6Apache DebianFedoraproject+3 more60Agile Plm Agile Product Lifecycle Management Integration PackApplication Testing Suite+57 moreJun 17, 2026 Aug 20, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more |
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, res...Show more |
6Apache DebianFasterxml+3 more18Banking Platform Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 moreJun 17, 2026 Jul 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more |
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class. |
2Oracle Xstream10Banking Platform Business Activity MonitoringCommunications Billing And Revenue Management Elastic Charging Engine+7 moreJun 17, 2026 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary...Show more |
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator...Show more |
1Osbs Client Project 1Osbs Client Jun 17, 2026 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsin...Show more |
3Fasterxml OracleRedhat7Clusterware Communications Instant Messaging ServerGlobal Lifecycle Management Opatch+4 moreNov 21, 2024 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. |
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data. |
3Debian FasterxmlRedhat3Debian Linux Enterprise LinuxJackson DatabindJun 17, 2026 Jun 24, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content,...Show more |
Akamai CloudTest before 58.30 allows remote code execution. |