CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,308)
page 115 of 166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-4385 | Hig | 0.48 | 7.3 | 0.04 | Sep 29, 2016 | The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils… | ||
| CVE-2026-73699 | Hig | 0.47 | 7.2 | 0.01 | Sep 10, 2026 | FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required… | ||
| CVE-2026-81757 | Hig | 0.47 | 7.2 | 0.00 | Aug 28, 2026 | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | ||
| CVE-2026-14558 | Hig | 0.47 | 7.2 | 0.01 | Aug 28, 2026 | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to… | ||
| CVE-2026-78276 | Hig | 0.47 | 7.2 | 0.01 | Aug 27, 2026 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | ||
| CVE-2026-78147 | Hig | 0.47 | 7.3 | 0.00 | Aug 23, 2026 | A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The… | ||
| CVE-2026-75987 | Hig | 0.47 | 7.3 | 0.00 | Aug 19, 2026 | A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remote exploitation of the attack is… | ||
| CVE-2026-66620 | Hig | 0.47 | 7.2 | 0.00 | Aug 18, 2026 | Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | ||
| CVE-2026-19826 | Hig | 0.47 | 7.3 | 0.00 | Aug 14, 2026 | A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed… | ||
| CVE-2026-66256 | Hig | 0.47 | 7.2 | 0.01 | Aug 13, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. … | ||
| CVE-2026-27380 | Hig | 0.47 | 7.2 | 0.00 | Aug 13, 2026 | Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. | ||
| CVE-2026-65549 | Hig | 0.47 | 7.2 | 0.00 | Aug 6, 2026 | Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | ||
| CVE-2026-39499 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | ||
| CVE-2026-39498 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. | ||
| CVE-2026-39481 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | ||
| CVE-2026-39472 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | ||
| CVE-2026-39471 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. | ||
| CVE-2026-39434 | Hig | 0.47 | 7.2 | 0.00 | Jun 15, 2026 | Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. | ||
| CVE-2026-37579 | Hig | 0.47 | 7.3 | 0.00 | May 28, 2026 | An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component | ||
| CVE-2026-8751 | Hig | 0.47 | 7.3 | 0.00 | May 17, 2026 | A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried… |
- risk 0.48cvss 7.3epss 0.04
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils…
- risk 0.47cvss 7.2epss 0.01
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required…
- risk 0.47cvss 7.2epss 0.00
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
- risk 0.47cvss 7.2epss 0.01
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to…
- risk 0.47cvss 7.2epss 0.01
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remote exploitation of the attack is…
- risk 0.47cvss 7.2epss 0.00
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed…
- risk 0.47cvss 7.2epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. …
- risk 0.47cvss 7.2epss 0.00
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
- risk 0.47cvss 7.2epss 0.00
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
- risk 0.47cvss 7.2epss 0.00
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
- risk 0.47cvss 7.2epss 0.00
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
- risk 0.47cvss 7.2epss 0.00
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
- risk 0.47cvss 7.3epss 0.00
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component
- risk 0.47cvss 7.3epss 0.00
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried…