VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 124 of 156
  • CVE-2020-4043HigJun 10, 2020
    risk 0.43cvss 7.7epss 0.03

    phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be…

  • CVE-2020-9484HigMay 20, 2020
    risk 0.43cvss 7.0epss 0.57

    When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore;…

  • CVE-2019-14439HigJul 30, 2019
    risk 0.43cvss 7.5epss 0.11

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

  • CVE-2026-63516MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62912MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

  • CVE-2026-71559HigAug 7, 2026
    risk 0.42cvss 7.5epss 0.01

    Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0…

  • CVE-2026-57859HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The…

  • CVE-2026-58163HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.01

    Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version…

  • CVE-2026-54499HigJul 8, 2026
    risk 0.42cvss 7.5epss 0.00

    Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to…

  • CVE-2026-55153HigJul 1, 2026
    risk 0.42cvss 7.1epss 0.00

    mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and…

  • CVE-2026-14265HigJul 1, 2026
    risk 0.42cvss 7.5epss 0.00

    Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query…

  • CVE-2026-27410MedJun 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

  • CVE-2026-1184MedMay 14, 2026
    risk 0.42cvss 6.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation.

  • CVE-2026-42521MedApr 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers…

  • CVE-2026-6857HigApr 22, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows…

  • CVE-2026-33337HigApr 17, 2026
    risk 0.42cvss 7.5epss 0.01

    Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bounds, allowing a cstring longer…

  • CVE-2026-35464HigApr 7, 2026
    risk 0.42cvss 7.5epss 0.01

    pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in this set and passes the existing path…

  • CVE-2026-34202HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.01

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a…

  • CVE-2026-1286MedMar 10, 2026
    risk 0.42cvss 6.5epss 0.00

    CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.

  • CVE-2026-1542MedFeb 28, 2026
    risk 0.42cvss 6.5epss 0.00

    The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.