CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists...Show more |
An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list, thus all...Show more |
4Debian FasterxmlNetapp+1 more26Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+23 moreAug 25, 2026 Aug 25, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). |
1Openrobotics 1Robot Operating System Jun 17, 2026 Aug 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creat...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Aug 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID...Show more |
2Oracle Vmware8Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+5 moreJun 17, 2026 Jul 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to...Show more |
1Vmware 2Gemfire Tanzu Gemfire For Virtual MachinesJun 17, 2026 Jul 31, 2020 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properl...Show more |
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary...Show more |
In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to i...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...Show more |
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Jul 20, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, becaus...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Jul 17, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM...Show more |
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the...Show more |
2Iconics Mitsubishielectric11Bizviz Energy AnalytixFacility Analytix+8 moreJun 17, 2026 Jul 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208...Show more |
2Iconics Mitsubishielectric11Bizviz Energy AnalytixFacility Analytix+8 moreJun 17, 2026 Jul 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC...Show more |
2Iconics Mitsubishielectric11Bizviz Energy AnalytixFacility Analytix+8 moreJun 17, 2026 Jul 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208...Show more |
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code execution because the URL's c...Show more |
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Jul 14, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution V...Show more |