VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 13 of 156
  • CVE-2016-7124CriSep 12, 2016
    risk 0.65cvss 9.8epss 0.17

    ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or…

  • CVE-2015-6420CriDec 15, 2015
    risk 0.65cvss 9.8epss 0.18

    Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and…

  • CVE-2026-59124CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

  • CVE-2026-18948CriAug 10, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the…

  • CVE-2026-16258CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.00

    The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before…

  • CVE-2026-50515CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

  • CVE-2026-65581CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

  • CVE-2026-65579CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

  • CVE-2026-65578CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

  • CVE-2026-65577CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

  • CVE-2026-65576CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

  • CVE-2026-65575CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

  • CVE-2026-65574CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

  • CVE-2026-65573CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

  • CVE-2026-65572CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

  • CVE-2026-65571CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

  • CVE-2026-65556CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

  • CVE-2026-65552CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

  • CVE-2026-28139CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

  • CVE-2026-66909CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to…