VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 13 of 166
  • CVE-2017-5983CriApr 10, 2017
    risk 0.65cvss 9.8epss 0.16

    The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

  • CVE-2014-8731CriMar 23, 2017
    risk 0.65cvss 9.8epss 0.12

    PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.

  • CVE-2016-6330CriSep 27, 2016
    risk 0.65cvss 9.8epss 0.11

    The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability…

  • CVE-2016-7124CriSep 12, 2016
    risk 0.65cvss 9.8epss 0.17

    ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or…

  • CVE-2015-6420CriDec 15, 2015
    risk 0.65cvss 9.8epss 0.19

    Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and…

  • CVE-2026-81657CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

  • CVE-2026-93467CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.01

    The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

  • CVE-2026-20242CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure…

  • CVE-2026-20307CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged…

  • CVE-2023-54398CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can…

  • CVE-2026-90919CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious…

  • CVE-2026-78006CriSep 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires…

  • CVE-2026-82845CriSep 12, 2026
    risk 0.64cvss 9.9epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with…

  • CVE-2026-87719CriSep 12, 2026
    risk 0.64cvss 9.9epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and…

  • CVE-2026-62105CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

  • CVE-2026-62103CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

  • CVE-2026-12745CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12744CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12650CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-77092CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.