CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Farukawa 1Electric Consciousmap Jun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within...Show more |
In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead to local escalation of privilege to system_server with no additional ex...Show more |
1Jenkins 1Amazon Web Services Serverless Application Model Jun 17, 2026 Apr 16, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. |
Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. |
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the at...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 15, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897. |
7Canonical DebianFedoraproject+4 more217 Mode Transition Tool Active Iq Unified ManagerCloud Backup+18 moreJun 17, 2026 Apr 15, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to ex...Show more |
7Canonical DebianFedoraproject+4 more207 Mode Transition Tool Active Iq Unified ManagerCloud Backup+17 moreJun 17, 2026 Apr 15, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to ex...Show more |
1Sap 2Businessobjects Business Intelligence Platform Crystal Reports For Visual StudioJun 17, 2026 Apr 14, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization atta...Show more |
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects t...Show more |
4Debian FasterxmlNetapp+1 more18Active Iq Unified Manager Banking PlatformCommunications Contacts Server+15 moreJun 17, 2026 Apr 7, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). |
4Debian FasterxmlNetapp+1 more22Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+19 moreAug 25, 2026 Apr 7, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). |
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if th...Show more |
An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its...Show more |
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library ve...Show more |
4Debian FasterxmlNetapp+1 more33Agile Plm Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+30 moreAug 25, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). |
4Debian FasterxmlNetapp+1 more32Agile Plm Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+29 moreAug 25, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). |