VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 138 of 167
  • CVE-2025-65035MedDec 19, 2025
    risk 0.42cvss 6.4epss 0.00

    pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability…

  • CVE-2025-63617MedNov 10, 2025
    risk 0.42cvss 6.5epss 0.00

    ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

  • CVE-2025-61505MedOct 10, 2025
    risk 0.42cvss 6.5epss 0.00

    e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized…

  • CVE-2025-60834MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

  • CVE-2025-60830MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.

  • CVE-2025-60828MedOct 8, 2025
    risk 0.42cvss 6.5epss 0.00

    WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

  • CVE-2025-9260MedSep 3, 2025
    risk 0.42cvss 6.5epss 0.01

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible…

  • CVE-2025-25692MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-25691MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-4393MedJul 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950…

  • CVE-2025-43713MedJul 3, 2025
    risk 0.42cvss 6.5epss 0.00

    ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be…

  • CVE-2025-3857HigApr 21, 2025
    risk 0.42cvss 7.5epss 0.01

    When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, this triggers an infinite…

  • CVE-2025-2485HigMar 28, 2025
    risk 0.42cvss 7.5epss 0.01

    The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This makes it possible for…

  • CVE-2025-30160HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This…

  • CVE-2024-10942HigMar 13, 2025
    risk 0.42cvss 7.5epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers…

  • CVE-2025-24357HigJan 27, 2025
    risk 0.42cvss 7.5epss 0.01

    vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When…

  • CVE-2024-12627HigJan 11, 2025
    risk 0.42cvss 7.5epss 0.01

    The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.5 via deserialization of untrusted input from post content passed to the capture_email…

  • CVE-2024-52306HigNov 13, 2024
    risk 0.42cvss 7.6epss 0.01

    FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.

  • CVE-2024-47072HigNov 8, 2024
    risk 0.42cvss 7.5epss 0.02

    XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is…

  • CVE-2024-9917MedOct 13, 2024
    risk 0.42cvss 6.3epss 0.09

    A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack…