CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this is...Show more |
2Debian Gosa Project2Debian Linux GosaJun 17, 2026 Dec 31, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the w...Show more |
Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed...Show more |
An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code exec...Show more |
6Apache CanonicalDebian+3 more17Application Testing Suite BookkeeperCommunications Network Integrity+14 moreJun 17, 2026 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t...Show more |
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Man...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrust...Show more |
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable...Show more |
1Divisait 4Dv2eemvc Proxia PhrProxia Suite+1 moreJun 17, 2026 Dec 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows re...Show more |
1Drupal 1Views Dynamic Field Jun 17, 2026 Dec 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names obj...Show more |
1Redhat 2Edeploy Jboss Enterprise Web ServerNov 21, 2024 Dec 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eDeploy has RCE via cPickle deserialization of untrusted data |
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. |
1Siemens 1Sppa T3000 Application Server Jun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifica...Show more |
1Siemens 1Sppa T3000 Application Server Jun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote cod...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxLeapJun 17, 2026 Dec 12, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and c...Show more |
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a pac...Show more |
1Telerik 1Ui For Asp.net Ajax Jun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-201...Show more |
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code. |
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class,...Show more |
1Dell 1Emc Storage Monitoring And Reporting Jun 17, 2026 Nov 26, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a craft...Show more |