CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 13 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-7124 | Cri | 0.65 | 9.8 | 0.17 | Sep 12, 2016 | ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or… | ||
| CVE-2015-6420 | Cri | 0.65 | 9.8 | 0.18 | Dec 15, 2015 | Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and… | ||
| CVE-2026-59124 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-18948 | Cri | 0.64 | 9.9 | 0.01 | Aug 10, 2026 | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the… | ||
| CVE-2026-16258 | Cri | 0.64 | 9.8 | 0.00 | Aug 7, 2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before… | ||
| CVE-2026-50515 | Cri | 0.64 | 9.9 | 0.01 | Aug 7, 2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65581 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | ||
| CVE-2026-65579 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | ||
| CVE-2026-65578 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | ||
| CVE-2026-65577 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||
| CVE-2026-65576 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | ||
| CVE-2026-65575 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | ||
| CVE-2026-65574 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | ||
| CVE-2026-65573 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | ||
| CVE-2026-65572 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | ||
| CVE-2026-65571 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | ||
| CVE-2026-65556 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | ||
| CVE-2026-65552 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | ||
| CVE-2026-28139 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||
| CVE-2026-66909 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to… |
- risk 0.65cvss 9.8epss 0.17
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or…
- risk 0.65cvss 9.8epss 0.18
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and…
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the…
- risk 0.64cvss 9.8epss 0.00
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before…
- risk 0.64cvss 9.9epss 0.01
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
- risk 0.64cvss 9.8epss 0.00
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
- risk 0.64cvss 9.8epss 0.01
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to…