CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
download.php in inoERP 4.15 allows SQL injection through insecure deserialization. |
1Bmc 1Myit Digital Workplace Jun 17, 2026 Sep 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running t...Show more |
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow...Show more |
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuratio...Show more |
6Debian FasterxmlFedoraproject+3 more17Banking Platform Customer Management And Segmentation FoundationDebian Linux+14 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. |
6Debian FasterxmlFedoraproject+3 more19Banking Platform Customer Management And Segmentation FoundationDebian Linux+16 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. |
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../.....Show more |
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine,...Show more |
1Gravitatedesign 1Gravitate Qa Tracker Nov 21, 2024 Sep 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. |
1Sitebuilder Dynamic Components Project 1Sitebuilder Dynamic Components Nov 21, 2024 Sep 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. |
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code exec...Show more |
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web...Show more |
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2. |
1Strategy11 1Formidable Form Builder Jun 17, 2026 Aug 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. |
2Fork Cms Spoon Library2Fork Cms Spoon LibraryJun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object. |
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. |
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the ....Show more |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. |