VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 123 of 156
  • CVE-2025-46738MedMay 12, 2025
    risk 0.43cvss 6.6epss 0.00

    An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

  • CVE-2025-39565MedApr 16, 2025
    risk 0.43cvss 6.6epss 0.01

    Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue affects MelaPress Login Security: from n/a through <= 2.1.0.

  • CVE-2021-27017MedFeb 7, 2025
    risk 0.43cvss 6.6epss 0.01

    Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

  • CVE-2024-13297MedJan 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.

  • CVE-2024-13296MedJan 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.

  • CVE-2024-13295MedJan 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.

  • CVE-2021-4451MedOct 16, 2024
    risk 0.43cvss 6.6epss 0.01

    The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits…

  • CVE-2024-43466MedSep 10, 2024
    risk 0.43cvss 6.5epss 0.04

    Microsoft SharePoint Server Denial of Service Vulnerability

  • CVE-2024-0668MedFeb 5, 2024
    risk 0.43cvss 6.6epss 0.01

    The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with…

  • CVE-2022-45083MedJan 19, 2024
    risk 0.43cvss 6.6epss 0.01

    Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form,…

  • CVE-2023-36381MedDec 28, 2023
    risk 0.43cvss 6.6epss 0.00

    Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.

  • CVE-2023-46154MedDec 19, 2023
    risk 0.43cvss 6.6epss 0.01

    Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

  • CVE-2022-39298HigOct 12, 2022
    risk 0.43cvss 7.7epss 0.01

    MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization and SEO, etc. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-front`, and ultimately leads to…

  • CVE-2022-39297HigOct 12, 2022
    risk 0.43cvss 7.7epss 0.01

    MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-cms`, and ultimately leads to the execution of arbitrary…

  • CVE-2021-23592HigMay 6, 2022
    risk 0.43cvss 7.7epss 0.02

    The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

  • CVE-2021-39140MedAug 23, 2021
    risk 0.43cvss 6.5epss 0.06

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of…

  • CVE-2021-23420HigAug 11, 2021
    risk 0.43cvss 7.7epss 0.03

    This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.

  • CVE-2021-21349MedMar 23, 2021
    risk 0.43cvss 6.1epss 0.47

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input…

  • CVE-2021-21345MedMar 23, 2021
    risk 0.43cvss 5.8epss 0.72

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user…

  • CVE-2020-10740MedJun 22, 2020
    risk 0.43cvss 6.6epss 0.02

    A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.