VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 122 of 156
  • CVE-2023-36777MedSep 12, 2023
    risk 0.44cvss 5.7epss 0.81

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2023-21209MedJun 28, 2023
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-25647HigMay 1, 2022
    risk 0.44cvss 7.7epss 0.12

    The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

  • CVE-2021-4118HigDec 23, 2021
    risk 0.44cvss 7.8epss 0.01

    pytorch-lightning is vulnerable to Deserialization of Untrusted Data

  • CVE-2021-25738MedOct 11, 2021
    risk 0.44cvss 6.7epss 0.00

    Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

  • CVE-2021-3040MedJun 10, 2021
    risk 0.44cvss 6.7epss 0.01

    An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.

  • CVE-2021-3035MedApr 20, 2021
    risk 0.44cvss 6.7epss 0.01

    An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.

  • CVE-2020-24164HigSep 11, 2020
    risk 0.44cvss 7.8epss 0.01

    A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java…

  • CVE-2013-7489MedJun 26, 2020
    risk 0.44cvss 6.8epss 0.01

    The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

  • CVE-2019-12086HigMay 17, 2019
    risk 0.44cvss 7.5epss 0.22

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the…

  • CVE-2018-1000167HigApr 18, 2018
    risk 0.44cvss 7.8epss 0.04

    OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can…

  • CVE-2018-1000074HigMar 13, 2018
    risk 0.44cvss 7.8epss 0.03

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can…

  • CVE-2026-68756MedAug 12, 2026
    risk 0.43cvss 6.6epss 0.00

    A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

  • CVE-2026-12115MedJun 17, 2026
    risk 0.43cvss 6.6epss 0.01

    The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…

  • CVE-2026-7566MedJun 6, 2026
    risk 0.43cvss 6.6epss 0.00

    The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and…

  • CVE-2026-48919MedMay 27, 2026
    risk 0.43cvss 6.6epss 0.00

    Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

  • CVE-2026-48917MedMay 27, 2026
    risk 0.43cvss 6.6epss 0.00

    Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

  • CVE-2025-67779HigDec 12, 2025
    risk 0.43cvss 7.5epss 0.20

    It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads…

  • CVE-2025-67535MedDec 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.

  • CVE-2025-54053MedAug 20, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2.