VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 150 of 156
  • CVE-2026-24240HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-10538HigJul 1, 2026
    risk 0.00cvss 8.0epss 0.00

    Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an…

  • CVE-2026-56700CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.02

    Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection…

  • CVE-2026-7871CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.

  • CVE-2026-13759HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget…

  • CVE-2026-12240HigJun 30, 2026
    risk 0.00cvss 8.0epss 0.00

    The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access…

  • CVE-2026-46386CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a…

  • CVE-2026-57527HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState…

  • CVE-2026-56057CriJun 26, 2026
    risk 0.00cvss 9.8epss 0.00

    Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

  • CVE-2026-56055HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

  • CVE-2026-56032CriJun 26, 2026
    risk 0.00cvss 9.8epss 0.01

    Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

  • CVE-2026-56031HigJun 26, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

  • CVE-2025-71340HigJun 25, 2026
    risk 0.00cvss 8.1epss 0.00

    picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the file is loaded via pickle.load(),…

  • CVE-2026-56053HigJun 25, 2026
    risk 0.00cvss 8.8epss 0.00

    Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

  • CVE-2026-49108CriJun 17, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

  • CVE-2026-40757HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

  • CVE-2026-40756HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

  • CVE-2026-40752HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

  • CVE-2026-40738HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

  • CVE-2026-40733HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.