VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 154 of 167
  • CVE-2022-2886MedAug 19, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of…

  • CVE-2022-20195MedJun 15, 2022
    risk 0.33cvss 5.0epss 0.00

    In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2026-13371MedJul 3, 2026
    risk 0.32cvss 4.9epss 0.01

    An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.

  • CVE-2025-53393MedJun 28, 2025
    risk 0.32cvss 6.0epss 0.00

    In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

  • CVE-2024-9953MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.00

    A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the…

  • CVE-2019-12814MedJun 19, 2019
    risk 0.32cvss 5.9epss 0.11

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker…

  • CVE-2026-81319MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption. AshCloak.Calculations.Decrypt…

  • CVE-2025-15438MedJan 2, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be…

  • CVE-2025-12058MedOct 29, 2025
    risk 0.31cvss —epss 0.00

    The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during…

  • CVE-2025-2180MedAug 13, 2025
    risk 0.31cvss —epss 0.00

    An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov…

  • CVE-2025-2855MedMar 27, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserialization. The attack may be launched…

  • CVE-2025-2043MedMar 6, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be…

  • CVE-2025-1556MedFeb 22, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads to deserialization. The attack may be initiated remotely.…

  • CVE-2025-0734MedJan 27, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been…

  • CVE-2024-3431MedApr 7, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&c=Field&a=channel_edit of the component Backend. The manipulation of the argument channel_id leads to deserialization. The attack…

  • CVE-2023-32636MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.01

    A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib…

  • CVE-2023-0960MedFeb 22, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be launched remotely. The…

  • CVE-2021-35227MedOct 21, 2021
    risk 0.31cvss 4.7epss 0.00

    The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

  • CVE-2018-15425MedOct 5, 2018
    risk 0.31cvss 4.7epss 0.02

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

  • CVE-2026-2970MedFeb 23, 2026
    risk 0.30cvss 4.6epss 0.01

    A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization. The attack requires being on the local…