VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 148 of 156
  • CVE-2026-54118HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

  • CVE-2026-54117HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

  • CVE-2026-50652HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

  • CVE-2026-12583HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…

  • CVE-2026-58233HigJul 14, 2026
    risk 0.00cvss 7.6epss 0.00

    SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system.…

  • CVE-2026-59521HigJul 13, 2026
    risk 0.00cvss 7.2epss 0.00

    Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

  • CVE-2026-59518CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

  • CVE-2026-57770CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

  • CVE-2026-57744CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

  • CVE-2026-57738CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

  • CVE-2026-57724CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

  • CVE-2026-57713HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

  • CVE-2026-57371HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

  • CVE-2026-15535MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument…

  • CVE-2026-15531MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to…

  • CVE-2026-15529MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to…

  • CVE-2026-58281HigJul 11, 2026
    risk 0.00cvss 8.3epss 0.01

    Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-55175HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code…

  • CVE-2026-54469HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

  • CVE-2026-59827CriJul 9, 2026
    risk 0.00cvss 9.9epss 0.01

    Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native…