VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 105 of 166
  • CVE-2025-62703HigNov 25, 2025
    risk 0.50cvss 8.8epss 0.01

    Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In version 0.9.2 and prior, there is a remote code execution vulnerability by pickle deserialization via FlaskRPCServer. The…

  • CVE-2025-62164HigNov 21, 2025
    risk 0.50cvss 8.8epss 0.01

    vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and potentially remote code execution (RCE), exists in the Completions API endpoint. When…

  • CVE-2025-58757HigSep 9, 2025
    risk 0.50cvss 8.8epss 0.01

    MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.py` automatically handles dictionary key-value pairs ending with a specific suffix and deserializes them…

  • CVE-2025-58756HigSep 9, 2025
    risk 0.50cvss 8.8epss 0.01

    MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely.…

  • CVE-2025-27818HigJun 10, 2025
    risk 0.50cvss 8.8epss 0.01

    A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based…

  • CVE-2025-47660HigMay 23, 2025
    risk 0.50cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

  • CVE-2025-31129HigMar 31, 2025
    risk 0.50cvss 8.8epss 0.01

    Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).

  • CVE-2024-10936HigJan 21, 2025
    risk 0.50cvss 8.8epss 0.01

    The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP…

  • CVE-2024-10957HigJan 4, 2025
    risk 0.50cvss 8.8epss 0.01

    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated…

  • CVE-2024-11394HigNov 22, 2024
    risk 0.50cvss 8.8epss 0.03

    Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2024-11393HigNov 22, 2024
    risk 0.50cvss 8.8epss 0.03

    Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2024-41151HigNov 18, 2024
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.

  • CVE-2024-10962HigNov 14, 2024
    risk 0.50cvss 8.8epss 0.01

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for…

  • CVE-2024-8922HigSep 27, 2024
    risk 0.50cvss 8.8epss 0.01

    The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untrusted input in enquiry_detail.php. This makes it possible for authenticated…

  • CVE-2024-43464HigSep 10, 2024
    risk 0.50cvss 7.2epss 0.36

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-42363HigAug 20, 2024
    risk 0.50cvss 8.8epss 0.01

    Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method where it is unsafely deserialized using the…

  • CVE-2024-5726HigJul 18, 2024
    risk 0.50cvss 8.8epss 0.01

    The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted input 'timelines-data' parameter. This makes it possible for authenticated attackers, with Contributor-level access…

  • CVE-2023-46801HigJul 15, 2024
    risk 0.50cvss 8.8epss 0.01

    In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the server and execute…

  • CVE-2024-38024HigJul 9, 2024
    risk 0.50cvss 7.2epss 0.45

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-4200HigMay 15, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.