VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 148 of 167
  • CVE-2025-55136MedAug 7, 2025
    risk 0.37cvss 5.7epss 0.00

    ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.

  • CVE-2025-24794MedJan 29, 2025
    risk 0.37cvss 6.7epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses…

  • CVE-2024-56515MedJan 16, 2025
    risk 0.37cvss 6.8epss 0.01

    Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbnail to invoke a…

  • CVE-2024-25117MedFeb 21, 2024
    risk 0.37cvss 6.8epss 0.01

    php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, which might leads to RCE on PHP < 8.0, and doesn't validate if external references are allowed. This…

  • CVE-2021-4178MedAug 24, 2022
    risk 0.37cvss 6.7epss 0.00

    A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

  • CVE-2026-94092MedSep 20, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The exploit is now public and may be…

  • CVE-2026-94091MedSep 20, 2026
    risk 0.36cvss 5.5epss 0.00

    A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is possible to initiate the attack remotely.…

  • CVE-2026-47878MedAug 27, 2026
    risk 0.36cvss 5.6epss 0.00

    DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring…

  • CVE-2026-47875MedAug 27, 2026
    risk 0.36cvss 5.6epss 0.00

    Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types…

  • CVE-2026-39578MedJun 17, 2026
    risk 0.36cvss 5.5epss 0.00

    Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.

  • CVE-2026-39577MedJun 17, 2026
    risk 0.36cvss 5.5epss 0.00

    Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.

  • CVE-2026-27794MedFeb 25, 2026
    risk 0.36cvss 6.6epss 0.01

    LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseCache` and opt nodes into caching via…

  • CVE-2026-2898MedFeb 22, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be…

  • CVE-2025-48086MedNov 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3.

  • CVE-2025-8871MedNov 5, 2025
    risk 0.36cvss 5.6epss 0.00

    The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input in the mime_content_type() function. This makes it possible for unauthenticated attackers to inject a PHP Object.…

  • CVE-2025-11938MedOct 19, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's…

  • CVE-2025-11345MedOct 6, 2025
    risk 0.36cvss 5.5epss 0.00

    A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve…

  • CVE-2025-54640MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.

  • CVE-2025-54639MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.

  • CVE-2025-54638MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of the ad service.