← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Godotengine
1Godot
Jun 17, 2026
May 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
1Sitecore
1Cms
Jun 17, 2026
May 31, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
1Sitecore
2Cms
Experience Platform
Jun 17, 2026
May 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a s...Show more
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.Show less
1Synacor
1Zimbra Collaboration Suite
Jun 17, 2026
May 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
1Adobe
1Coldfusion
Jun 17, 2026
May 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
1Ampache
1Ampache
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
1E107
1E107
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
1Hazelcast
1Hazelcast
Nov 21, 2024
May 22, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable cla...Show more
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.Show less
1Carts.guru
1Carts Guru
Jun 17, 2026
May 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
1Virim Project
1Virim
Jun 17, 2026
May 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.
2Debian
Fasterxml
2Debian Linux
Jackson Databind
Jun 17, 2026
May 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service h...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
May 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
1Sensiolabs
1Symfony
Jun 17, 2026
May 16, 2019
N/A· v4
7.1 HIGH· v3
6.5 MEDIUM· v2
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the delet...Show more
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.Show less
1Siemens
1Logo! Soft Comfort
Jun 17, 2026
May 14, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3). The vulnerability could allow an attacker to execute arbitrary code if the attacker tricks a legitimate user to open a manipulated project....Show more
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3). The vulnerability could allow an attacker to execute arbitrary code if the attacker tricks a legitimate user to open a manipulated project. In order to exploit the vulnerability, a valid user must open a manipulated project file. No further privileges are required on the target system. The vulnerability could compromise the confidentiality, integrity and availability of the engineering station. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
5Debian
DrupalFedoraproject+2 more
5Debian Linux
DrupalFedora+2 more
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as de...Show more
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.Show less
1Typo3
1Pharstreamwrapper
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protecti...Show more
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.Show less