VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 115 of 166
  • CVE-2016-4385HigSep 29, 2016
    risk 0.48cvss 7.3epss 0.04

    The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils…

  • CVE-2026-73699HigSep 10, 2026
    risk 0.47cvss 7.2epss 0.01

    FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required…

  • CVE-2026-81757HigAug 28, 2026
    risk 0.47cvss 7.2epss 0.00

    Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

  • CVE-2026-14558HigAug 28, 2026
    risk 0.47cvss 7.2epss 0.01

    The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to…

  • CVE-2026-78276HigAug 27, 2026
    risk 0.47cvss 7.2epss 0.01

    Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

  • CVE-2026-78147HigAug 23, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The…

  • CVE-2026-75987HigAug 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remote exploitation of the attack is…

  • CVE-2026-66620HigAug 18, 2026
    risk 0.47cvss 7.2epss 0.00

    Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

  • CVE-2026-19826HigAug 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed…

  • CVE-2026-66256HigAug 13, 2026
    risk 0.47cvss 7.2epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. …

  • CVE-2026-27380HigAug 13, 2026
    risk 0.47cvss 7.2epss 0.00

    Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.

  • CVE-2026-65549HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.00

    Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.

  • CVE-2026-39499HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.

  • CVE-2026-39498HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

  • CVE-2026-39481HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

  • CVE-2026-39472HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

  • CVE-2026-39471HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

  • CVE-2026-39434HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.

  • CVE-2026-37579HigMay 28, 2026
    risk 0.47cvss 7.3epss 0.00

    An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component

  • CVE-2026-8751HigMay 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried…