VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 147 of 156
  • CVE-2026-61246HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60439HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60373HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60372CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-60369CriJul 22, 2026
    risk 0.00cvss 9.9epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60367CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-60366CriJul 22, 2026
    risk 0.00cvss 10.0epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-24232MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-64606CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version…

  • CVE-2026-63767CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces.…

  • CVE-2026-28220HigJul 20, 2026
    risk 0.00cvss 8.4epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster…

  • CVE-2026-8476CriJul 17, 2026
    risk 0.00cvss 9.9epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity…

  • CVE-2026-15008HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.01

    The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it…

  • CVE-2026-47472HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and…

  • CVE-2026-24233HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code…

  • CVE-2026-24227MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-24220MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-55944CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

  • CVE-2026-50509HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55009HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.02

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.