← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Inoideas
1Inoerp
Jun 17, 2026
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
1Bmc
1Myit Digital Workplace
Jun 17, 2026
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running t...Show more
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.Show less
1Microfocus
1Service Manager
Jun 17, 2026
Sep 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow...Show more
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.Show less
1Apache
1Tapestry
Jun 17, 2026
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuratio...Show more
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the webapp's AppModule class, the value of this symbol could be used to craft a Java deserialization attack, thus running malicious injected Java code. The vector would be the t:formdata parameter from the Form component.Show less
6Debian
FasterxmlFedoraproject+3 more
17Banking Platform
Customer Management And Segmentation FoundationDebian Linux+14 more
Jun 17, 2026
Sep 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
6Debian
FasterxmlFedoraproject+3 more
19Banking Platform
Customer Management And Segmentation FoundationDebian Linux+16 more
Jun 17, 2026
Sep 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
1Pimcore
1Pimcore
Jun 17, 2026
Sep 14, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../.....Show more
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.Show less
1Apache
1Ofbiz
Jun 17, 2026
Sep 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine,...Show more
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16Show less
1Gravitatedesign
1Gravitate Qa Tracker
Nov 21, 2024
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
1Sitebuilder Dynamic Components Project
1Sitebuilder Dynamic Components
Nov 21, 2024
Sep 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
1Alfresco
1Alfresco
Jun 17, 2026
Sep 5, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code exec...Show more
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution on the victim machine. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.Show less
1Epignosishq
1Efront Lms
Jun 17, 2026
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web...Show more
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.Show less
1Eventum Project
1Eventum
Nov 21, 2024
Sep 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.
1Strategy11
1Formidable Form Builder
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
2Fork Cms
Spoon Library
2Fork Cms
Spoon Library
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
1Tribulant
1Newsletters
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
1Mirasys
1Mirasys Vms
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the ....Show more
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.Show less
1Optiontree Project
1Optiontree
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
1Optiontree Project
1Optiontree
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
1Optiontree Project
1Optiontree
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.