VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 143 of 156
  • CVE-2026-0895MedJan 20, 2026
    risk 0.27cvss epss 0.00

    The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a…

  • CVE-2025-48459MedSep 24, 2025
    risk 0.27cvss 5.3epss 0.00

    Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.

  • CVE-2025-5174MedMay 26, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pypickle/pypickle.py. The manipulation leads to deserialization. Local access is required to approach this attack. The exploit has…

  • CVE-2025-5148MedMay 25, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py of the component Pickle Data Handler. The manipulation leads…

  • CVE-2023-27531MedJan 9, 2025
    risk 0.27cvss 5.3epss 0.01

    There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

  • CVE-2024-29032MedMar 20, 2024
    risk 0.27cvss 5.3epss 0.00

    Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and prior to version 0.21.2, deserializing json data using `qiskit_ibm_runtime.RuntimeDecoder` can lead…

  • CVE-2022-33900MedAug 22, 2022
    risk 0.27cvss 4.1epss 0.01

    PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

  • CVE-2022-2870MedAug 17, 2022
    risk 0.27cvss 4.1epss 0.01

    A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier…

  • CVE-2021-34394MedJun 22, 2021
    risk 0.27cvss 4.2epss 0.00

    Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data…

  • CVE-2021-34393MedJun 22, 2021
    risk 0.27cvss 4.2epss 0.00

    Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

  • CVE-2019-2391MedMar 31, 2020
    risk 0.27cvss 4.2epss 0.01

    Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.

  • CVE-2026-7317MedApr 28, 2026
    risk 0.26cvss 5.0epss 0.00

    A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization.…

  • CVE-2024-28859MedMar 15, 2024
    risk 0.26cvss 5.0epss 0.01

    Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 support. Symfony 1 has a gadget chain due to vulnerable Swift Mailer dependency that would enable an attacker to get remote code…

  • CVE-2021-21371MedMar 10, 2021
    risk 0.26cvss 5.0epss 0.00

    Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the vulnerabilities' current state. It published in pypi as "tenable-jira-cloud". In tenable-jira-cloud before version 1.1.21, it is…

  • CVE-2017-15703MedJan 25, 2018
    risk 0.26cvss 5.0epss 0.01

    Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on the Apache NiFi…

  • CVE-2025-20276LowJun 4, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This…

  • CVE-2024-34274LowMay 21, 2024
    risk 0.25cvss 3.9epss 0.00

    OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vulnerability only affects products that…

  • CVE-2023-26592LowFeb 14, 2024
    risk 0.25cvss 3.8epss 0.00

    Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2014-1420LowSep 11, 2020
    risk 0.25cvss 3.8epss 0.01

    On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is…

  • CVE-2025-13805LowDec 1, 2025
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component…