VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 108 of 156
  • CVE-2023-27459HigMar 26, 2024
    risk 0.48cvss 7.4epss 0.01

    Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.

  • CVE-2024-1225HigFeb 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file /application/index/controller/Pay.php. The manipulation of the argument callback_class leads to deserialization. The attack can…

  • CVE-2024-1032HigJan 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of the component Test Connection Handler. The manipulation leads to deserialization.…

  • CVE-2024-0739HigJan 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The manipulation of the argument install leads to deserialization. It is possible to launch the attack remotely. The…

  • CVE-2024-0603HigJan 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The…

  • CVE-2023-46147HigDec 20, 2023
    risk 0.48cvss 7.4epss 0.00

    Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

  • CVE-2023-37941MedSep 6, 2023
    risk 0.48cvss 6.6epss 0.29

    If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only…

  • CVE-2023-1347HigMay 8, 2023
    risk 0.48cvss 7.2epss 0.16

    The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

  • CVE-2023-1669HigMay 2, 2023
    risk 0.48cvss 7.2epss 0.18

    The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2023-21568HigFeb 14, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability

  • CVE-2022-36957HigOct 20, 2022
    risk 0.48cvss 7.2epss 0.13

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2019-6834HigApr 13, 2022
    risk 0.48cvss 7.3epss 0.01

    A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected…

  • CVE-2022-0749HigMar 17, 2022
    risk 0.48cvss 7.4epss 0.02

    This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for…

  • CVE-2021-39207HigSep 10, 2021
    risk 0.48cvss 8.4epss 0.02

    parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. This security bug is…

  • CVE-2021-29505HigMay 28, 2021
    risk 0.48cvss 7.5epss 0.77

    XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the…

  • CVE-2020-12525HigJan 22, 2021
    risk 0.48cvss 7.3epss 0.01

    M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

  • CVE-2018-1851HigOct 31, 2018
    risk 0.48cvss 7.3epss 0.04

    IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute…

  • CVE-2017-1677HigMar 22, 2018
    risk 0.48cvss 7.4epss 0.01

    IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.

  • CVE-2016-4385HigSep 29, 2016
    risk 0.48cvss 7.3epss 0.04

    The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils…

  • CVE-2026-19826HigAug 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed…