CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 151 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-39576 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. | ||
| CVE-2026-39560 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. | ||
| CVE-2026-39556 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. | ||
| CVE-2026-39445 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. | ||
| CVE-2026-39442 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. | ||
| CVE-2025-69130 | Hig | 0.00 | 8.8 | 0.00 | Jun 17, 2026 | Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. | ||
| CVE-2025-69127 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | ||
| CVE-2025-69111 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. | ||
| CVE-2025-60236 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. | ||
| CVE-2025-60231 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. | ||
| CVE-2025-60230 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. | ||
| CVE-2025-60229 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. | ||
| CVE-2025-52998 | Cri | 0.00 | 9.8 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the… | ||
| CVE-2025-50198 | Med | 0.00 | 4.9 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version… | ||
| CVE-2026-24892 | Hig | 0.00 | 7.5 | 0.01 | Feb 20, 2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized… | ||
| CVE-2025-13711 | Hig | 0.00 | 7.8 | 0.00 | Dec 23, 2025 | Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the… | ||
| CVE-2025-13709 | Hig | 0.00 | 7.8 | 0.00 | Dec 23, 2025 | Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in… | ||
| CVE-2025-34449 | Cri | 0.00 | 9.1 | 0.00 | Dec 18, 2025 | Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory… | ||
| CVE-2025-64164 | Cri | 0.00 | 9.8 | 0.01 | Nov 6, 2025 | Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface injection). This issue is fixed… | ||
| CVE-2025-62420 | Hig | 0.00 | 8.8 | 0.01 | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. The getJdbc function in H2.java checks if the jdbcUrl starts with jdbc:h2 but returns a separate jdbc… |
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
- risk 0.00cvss 8.8epss 0.00
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
- risk 0.00cvss 9.8epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the…
- risk 0.00cvss 4.9epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version…
- risk 0.00cvss 7.5epss 0.01
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized…
- risk 0.00cvss 7.8epss 0.00
Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the…
- risk 0.00cvss 7.8epss 0.00
Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in…
- risk 0.00cvss 9.1epss 0.00
Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory…
- risk 0.00cvss 9.8epss 0.01
Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface injection). This issue is fixed…
- risk 0.00cvss 8.8epss 0.01
DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. The getJdbc function in H2.java checks if the jdbcUrl starts with jdbc:h2 but returns a separate jdbc…