VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 152 of 156
  • CVE-2025-62419HigOct 17, 2025
    risk 0.00cvss 7.5epss 0.00

    DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME,…

  • CVE-2025-59050HigSep 16, 2025
    risk 0.00cvss 8.4epss 0.00

    Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled data received in a WM_COPYDATA message using BinaryFormatter.Deserialize without prior validation or authentication, allowing a local process at the same…

  • CVE-2025-58748CriSep 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided JDBC URL starts with jdbc:h2. This lack of validation allows a crafted JDBC configuration that…

  • CVE-2025-58046CriSep 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code execution due to insufficient filtering in the getJdbc method of the io.dataease.datasource.type.Impala class.…

  • CVE-2025-58163HigSep 3, 2025
    risk 0.00cvss 8.8epss 0.01

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vulnerability that allows authenticated attackers with knowledge of the application's APP_KEY to achieve remote code…

  • CVE-2025-55010CriAug 12, 2025
    risk 0.00cvss 9.1epss 0.01

    Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by modifying the event["data"]…

  • CVE-2025-54366HigJul 26, 2025
    risk 0.00cvss 8.8epss 0.01

    FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical deserialization vulnerability in the /conversation/ajax endpoint that allows authenticated users with knowledge of the…

  • CVE-2025-7504HigJul 12, 2025
    risk 0.00cvss 7.5epss 0.01

    The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known…

  • CVE-2025-48389HigMay 29, 2025
    risk 0.00cvss 7.2epss 0.01

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an…

  • CVE-2025-47784CriMay 15, 2025
    risk 0.00cvss 9.8epss 0.00

    Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return…

  • CVE-2024-12433CriMar 20, 2025
    risk 0.00cvss 9.8epss 0.02

    A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers to join the group communication without restrictions.…

  • CVE-2024-11039HigMar 20, 2025
    risk 0.00cvss 8.8epss 0.02

    A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue…

  • CVE-2025-27781CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take user-supplied input (e.g. a path to a model) and pass that value to the…

  • CVE-2025-27780CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in model_information.py takes user-supplied input (e.g. a path to a model) and pass that value to the `run_model_information_script`…

  • CVE-2025-27779CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a path to a model) and pass that value to…

  • CVE-2025-27778CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of the Applio repository but not attached to…

  • CVE-2024-47092CriMar 3, 2025
    risk 0.00cvss 9.8epss 0.00

    Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

  • CVE-2025-23045CriJan 28, 2025
    risk 0.00cvss 9.8epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT…

  • CVE-2024-54136CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/upload.php where the user supplied input via collection get parameter is directly…

  • CVE-2024-54135CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/photo_upload.php within the decode_key function. User inputs were supplied…