CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 150 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24240 | Hig | 0.00 | 7.8 | 0.00 | Jul 1, 2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | ||
| CVE-2026-10538 | Hig | 0.00 | 8.0 | 0.00 | Jul 1, 2026 | Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an… | ||
| CVE-2026-56700 | Cri | 0.00 | 9.8 | 0.02 | Jun 30, 2026 | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection… | ||
| CVE-2026-7871 | Cri | 0.00 | 9.8 | 0.00 | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity. | ||
| CVE-2026-13759 | Hig | 0.00 | 7.5 | 0.00 | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget… | ||
| CVE-2026-12240 | Hig | 0.00 | 8.0 | 0.00 | Jun 30, 2026 | The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access… | ||
| CVE-2026-46386 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a… | ||
| CVE-2026-57527 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState… | ||
| CVE-2026-56057 | Cri | 0.00 | 9.8 | 0.00 | Jun 26, 2026 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | ||
| CVE-2026-56055 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | ||
| CVE-2026-56032 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | ||
| CVE-2026-56031 | Hig | 0.00 | 8.1 | 0.00 | Jun 26, 2026 | Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. | ||
| CVE-2025-71340 | Hig | 0.00 | 8.1 | 0.00 | Jun 25, 2026 | picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the file is loaded via pickle.load(),… | ||
| CVE-2026-56053 | Hig | 0.00 | 8.8 | 0.00 | Jun 25, 2026 | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | ||
| CVE-2026-49108 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Moderno < 1.43 versions. | ||
| CVE-2026-40757 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. | ||
| CVE-2026-40756 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. | ||
| CVE-2026-40752 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. | ||
| CVE-2026-40738 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. | ||
| CVE-2026-40733 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. |
- risk 0.00cvss 7.8epss 0.00
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
- risk 0.00cvss 8.0epss 0.00
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an…
- risk 0.00cvss 9.8epss 0.02
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection…
- risk 0.00cvss 9.8epss 0.00
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
- risk 0.00cvss 7.5epss 0.00
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget…
- risk 0.00cvss 8.0epss 0.00
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access…
- risk 0.00cvss 9.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a…
- risk 0.00cvss 8.8epss 0.00
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState…
- risk 0.00cvss 9.8epss 0.00
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
- risk 0.00cvss 8.8epss 0.00
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
- risk 0.00cvss 9.8epss 0.01
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
- risk 0.00cvss 8.1epss 0.00
picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the file is loaded via pickle.load(),…
- risk 0.00cvss 8.8epss 0.00
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.