← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ethereum
1Ethereumj
Nov 21, 2024
Jun 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS command...Show more
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.Show less
2Debian
Fasterxml
2Debian Linux
Jackson Databind
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the servi...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.Show less
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jun 18, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
1Shopware
1Shopware
Jun 17, 2026
Jun 13, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiat...Show more
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.Show less
1Adobe
1Coldfusion
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
1Parso Project
1Parso
Jun 17, 2026
Jun 6, 2019
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and th...Show more
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration.Show less
1Sitecore
1Experience Platform
Jun 17, 2026
Jun 6, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by s...Show more
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.Show less
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Godotengine
1Godot
Jun 17, 2026
May 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
1Sitecore
1Cms
Jun 17, 2026
May 31, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
1Sitecore
2Cms
Experience Platform
Jun 17, 2026
May 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a s...Show more
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.Show less
1Synacor
1Zimbra Collaboration Suite
Jun 17, 2026
May 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
1Adobe
1Coldfusion
Jun 17, 2026
May 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
1Ampache
1Ampache
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
1E107
1E107
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
1Hazelcast
1Hazelcast
Nov 21, 2024
May 22, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable cla...Show more
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.Show less