CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 148 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-54118 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-54117 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-50652 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-12583 | Hig | 0.00 | 8.1 | 0.00 | Jul 14, 2026 | The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress… | ||
| CVE-2026-58233 | Hig | 0.00 | 7.6 | 0.00 | Jul 14, 2026 | SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system.… | ||
| CVE-2026-59521 | Hig | 0.00 | 7.2 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | ||
| CVE-2026-59518 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | ||
| CVE-2026-57770 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8. | ||
| CVE-2026-57744 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. | ||
| CVE-2026-57738 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0. | ||
| CVE-2026-57724 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. | ||
| CVE-2026-57713 | Hig | 0.00 | 8.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6. | ||
| CVE-2026-57371 | Hig | 0.00 | 8.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0. | ||
| CVE-2026-15535 | Med | 0.00 | 6.3 | 0.00 | Jul 13, 2026 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument… | ||
| CVE-2026-15531 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to… | ||
| CVE-2026-15529 | Med | 0.00 | 6.3 | 0.00 | Jul 13, 2026 | A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to… | ||
| CVE-2026-58281 | Hig | 0.00 | 8.3 | 0.01 | Jul 11, 2026 | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-55175 | Hig | 0.00 | 7.5 | 0.01 | Jul 10, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code… | ||
| CVE-2026-54469 | Hig | 0.00 | 8.8 | 0.00 | Jul 10, 2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | ||
| CVE-2026-59827 | Cri | 0.00 | 9.9 | 0.01 | Jul 9, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native… |
- risk 0.00cvss 8.8epss 0.01
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.00cvss 8.8epss 0.01
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.00cvss 7.5epss 0.01
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 8.1epss 0.00
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…
- risk 0.00cvss 7.6epss 0.00
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system.…
- risk 0.00cvss 7.2epss 0.00
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- risk 0.00cvss 8.8epss 0.00
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
- risk 0.00cvss 8.8epss 0.00
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
- risk 0.00cvss 6.3epss 0.00
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument…
- risk 0.00cvss 5.3epss 0.00
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to…
- risk 0.00cvss 8.3epss 0.01
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.5epss 0.01
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code…
- risk 0.00cvss 8.8epss 0.00
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
- risk 0.00cvss 9.9epss 0.01
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native…