CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicio...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudJun 17, 2026 Jul 9, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially c...Show more |
1Atlassian 2Jira Jira Software Data CenterJun 17, 2026 Jul 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server an...Show more |
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. |
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution. |
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly...Show more |
Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py. |
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not sa...Show more |
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php. |
3Debian OpensuseRubyonrails3Debian Linux LeapRailsJun 17, 2026 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more |
3Debian OpensuseRubyonrails4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. |
4Debian FasterxmlNetapp+1 more15Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+12 moreAug 25, 2026 Jun 16, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). |
3Fasterxml NetappOracle13Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+10 moreAug 25, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). |
4Debian FasterxmlNetapp+1 more14Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+11 moreAug 25, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). |
4Debian FasterxmlNetapp+1 more16Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+13 moreAug 25, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms....Show more |
2Broadcom Pivotal Software2Spring Batch Spring BatchSep 1, 2026 Jun 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". S...Show more |
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed....Show more |
1Phpmussel Project 1Phpmussel Jun 17, 2026 Jun 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested,...Show more |
1Inductiveautomation 1Ignition Gateway Jun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 G...Show more |
1Inductiveautomation 1Ignition Gateway Jun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9...Show more |