CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,308)
page 15 of 166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73366 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | ||
| CVE-2026-73341 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | ||
| CVE-2026-59940 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without… | ||
| CVE-2026-32470 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||
| CVE-2024-13784 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2026 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated… | ||
| CVE-2026-28149 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-59124 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-18948 | Cri | 0.64 | 9.9 | 0.01 | Aug 10, 2026 | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the… | ||
| CVE-2026-16258 | Cri | 0.64 | 9.8 | 0.00 | Aug 7, 2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before… | ||
| CVE-2026-50515 | Cri | 0.64 | 9.9 | 0.01 | Aug 7, 2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65581 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | ||
| CVE-2026-65579 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | ||
| CVE-2026-65578 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | ||
| CVE-2026-65577 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||
| CVE-2026-65576 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | ||
| CVE-2026-65575 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | ||
| CVE-2026-65574 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | ||
| CVE-2026-65573 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | ||
| CVE-2026-65572 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | ||
| CVE-2026-65571 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. |
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
- risk 0.64cvss 9.8epss 0.01
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- risk 0.64cvss 9.8epss 0.01
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the…
- risk 0.64cvss 9.8epss 0.00
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before…
- risk 0.64cvss 9.9epss 0.01
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.