VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 14 of 156
  • CVE-2026-61484CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or…

  • CVE-2026-70554CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers…

  • CVE-2026-69098CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to…

  • CVE-2026-12118CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

  • CVE-2026-65883CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

  • CVE-2026-14512CriJul 28, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

  • CVE-2026-66713CriJul 28, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote…

  • CVE-2026-64608CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.00

    Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause…

  • CVE-2026-8024CriJun 18, 2026
    risk 0.64cvss 9.8epss 0.01

    A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

  • CVE-2026-54806CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

  • CVE-2026-54194CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.

  • CVE-2026-52706CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

  • CVE-2026-49107CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.

  • CVE-2026-49075CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

  • CVE-2026-42380CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

  • CVE-2026-40725CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

  • CVE-2026-39529CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

  • CVE-2026-27429CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

  • CVE-2025-69122CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.

  • CVE-2025-69108CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.