VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 140 of 156
  • CVE-2025-8708MedAug 8, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input…

  • CVE-2025-46567MedMay 1, 2025
    risk 0.33cvss 6.1epss 0.00

    LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files…

  • CVE-2025-0974MedFeb 3, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of…

  • CVE-2024-10749MedNov 4, 2024
    risk 0.33cvss 5.0epss 0.01

    A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack…

  • CVE-2024-45772MedSep 30, 2024
    risk 0.33cvss 5.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not…

  • CVE-2024-34075MedMay 3, 2024
    risk 0.33cvss 6.2epss 0.00

    kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method used in `Markov#generate` and `Markov#choose` allows a maliciously crafted string on the dataset to throw and stop the function…

  • CVE-2024-1748MedFeb 22, 2024
    risk 0.33cvss 5.0epss 0.01

    A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_file of the component Release Note Handler. The manipulation leads to deserialization. The attack can be initiated remotely. The…

  • CVE-2024-1432MedFeb 11, 2024
    risk 0.33cvss 5.0epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22 and classified as problematic. This issue affects the function apply_xseg of the file main.py. The manipulation leads to deserialization. The attack may be initiated…

  • CVE-2024-0960MedJan 27, 2024
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpickle.loads of the file \ai_flow\cli\commands\workflow_command.py. The manipulation leads to deserialization. The attack can be…

  • CVE-2024-0959MedJan 27, 2024
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gibson\utils\pposgd_fuse.py. The manipulation leads to deserialization. It is possible to launch the attack remotely. The complexity…

  • CVE-2023-6656MedDec 10, 2023
    risk 0.33cvss 5.0epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affected by this issue is some unknown functionality of the file DFLIMG/DFLJPG.py. The manipulation leads to deserialization. The attack…

  • CVE-2023-34050MedOct 19, 2023
    risk 0.33cvss 5.0epss 0.02

    In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list…

  • CVE-2023-23638MedMar 8, 2023
    risk 0.33cvss 5.0epss 0.05

    A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and…

  • CVE-2022-2886MedAug 19, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of…

  • CVE-2022-20195MedJun 15, 2022
    risk 0.33cvss 5.0epss 0.00

    In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2026-13371MedJul 3, 2026
    risk 0.32cvss 4.9epss 0.00

    An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.

  • CVE-2025-53393MedJun 28, 2025
    risk 0.32cvss 6.0epss 0.00

    In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

  • CVE-2024-9953MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.00

    A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the…

  • CVE-2019-12814MedJun 19, 2019
    risk 0.32cvss 5.9epss 0.11

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker…

  • CVE-2026-69659MedAug 9, 2026
    risk 0.31cvss epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in…