VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 141 of 156
  • CVE-2025-15438MedJan 2, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be…

  • CVE-2025-12058MedOct 29, 2025
    risk 0.31cvss epss 0.00

    The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during…

  • CVE-2025-2180MedAug 13, 2025
    risk 0.31cvss epss 0.00

    An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov…

  • CVE-2025-2855MedMar 27, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserialization. The attack may be launched…

  • CVE-2025-2043MedMar 6, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be…

  • CVE-2025-1556MedFeb 22, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads to deserialization. The attack may be initiated remotely.…

  • CVE-2025-0734MedJan 27, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been…

  • CVE-2024-3431MedApr 7, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&c=Field&a=channel_edit of the component Backend. The manipulation of the argument channel_id leads to deserialization. The attack…

  • CVE-2023-32636MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.01

    A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib…

  • CVE-2023-0960MedFeb 22, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be launched remotely. The…

  • CVE-2021-35227MedOct 21, 2021
    risk 0.31cvss 4.7epss 0.00

    The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

  • CVE-2018-15425MedOct 5, 2018
    risk 0.31cvss 4.7epss 0.02

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

  • CVE-2026-35502MedAug 11, 2026
    risk 0.30cvss epss 0.00

    Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable…

  • CVE-2026-2970MedFeb 23, 2026
    risk 0.30cvss 4.6epss 0.01

    A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization. The attack requires being on the local…

  • CVE-2026-7669MedMay 2, 2026
    risk 0.29cvss 5.6epss 0.00

    A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input…

  • CVE-2026-23685MedFeb 10, 2026
    risk 0.29cvss 4.4epss 0.00

    Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during…

  • CVE-2025-13467MedNov 25, 2025
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

  • CVE-2025-6279MedJun 19, 2025
    risk 0.29cvss 5.5epss 0.00

    A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to…

  • CVE-2024-34751MedMay 16, 2024
    risk 0.29cvss 4.4epss 0.00

    Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.

  • CVE-2024-34433MedMay 14, 2024
    risk 0.29cvss 4.4epss 0.01

    Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.