VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 144 of 156
  • CVE-2025-1741MedFeb 27, 2025
    risk 0.24cvss 4.7epss 0.00

    A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unknown functionality of the file src/admin/users.php of the component Admin Page. The manipulation of the argument query/q leads to deserialization. The attack…

  • CVE-2024-21217LowOct 15, 2024
    risk 0.24cvss 3.7epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK:…

  • CVE-2022-21624LowOct 18, 2022
    risk 0.24cvss 3.7epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0.…

  • CVE-2020-2757LowApr 15, 2020
    risk 0.24cvss 3.7epss 0.04

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2020-2756LowApr 15, 2020
    risk 0.24cvss 3.7epss 0.04

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2023-35815LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.01

    DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

  • CVE-2023-35814LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.01

    DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

  • CVE-2026-5473MedApr 3, 2026
    risk 0.22cvss 4.5epss 0.00

    A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The…

  • CVE-2024-27281MedMay 14, 2024
    risk 0.22cvss 4.5epss 0.02

    An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the…

  • CVE-2023-34382MedDec 19, 2023
    risk 0.22cvss 4.4epss 0.01

    Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from…

  • CVE-2022-29615LowJun 14, 2022
    risk 0.22cvss 3.4epss 0.00

    SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.

  • CVE-2019-16774MedDec 12, 2019
    risk 0.22cvss 4.4epss 0.01

    In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.

  • CVE-2019-12760LowJun 6, 2019
    risk 0.22cvss 3.3epss 0.02

    A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to…

  • CVE-2026-44501MedMay 14, 2026
    risk 0.21cvss 4.3epss 0.00

    DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This…

  • CVE-2024-29040MedJun 28, 2024
    risk 0.21cvss 4.3epss 0.00

    This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this…

  • CVE-2025-15117LowDec 28, 2025
    risk 0.20cvss 3.1epss 0.00

    A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer.java. Executing manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high…

  • CVE-2025-10252LowSep 11, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high…

  • CVE-2016-0750MedSep 11, 2018
    risk 0.20cvss 4.2epss 0.02

    The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

  • CVE-2026-10532LowJun 1, 2026
    risk 0.19cvss epss 0.00

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer…

  • CVE-2026-9828LowMay 28, 2026
    risk 0.19cvss epss 0.00

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or…