VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 156 of 167
  • CVE-2025-3250MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The manipulation leads to deserialization. The…

  • CVE-2024-13288MedJan 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.

  • CVE-2024-1858MedMar 29, 2024
    risk 0.28cvss 5.4epss 0.01

    The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.9 via deserialization of untrusted input through post meta data. This makes it possible for authenticated attackers, with…

  • CVE-2022-45845MedJan 19, 2024
    risk 0.28cvss 4.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

  • CVE-2023-30534MedSep 5, 2023
    risk 0.28cvss 4.3epss 0.03

    Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included,…

  • CVE-2023-34040MedAug 24, 2023
    risk 0.28cvss 5.3epss 0.02

    In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization…

  • CVE-2023-33008MedJul 7, 2023
    risk 0.28cvss 5.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and maybe use numbers too…

  • CVE-2023-3234MedJun 14, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/v1/PublicController.php. The manipulation leads to deserialization. The attack can be launched…

  • CVE-2018-1999042MedAug 23, 2018
    risk 0.28cvss 5.3epss 0.01

    A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.

  • CVE-2026-91842MedSep 15, 2026
    risk 0.27cvss 4.1epss 0.00

    A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be…

  • CVE-2026-16297MedAug 3, 2026
    risk 0.27cvss 4.1epss 0.00

    The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain…

  • CVE-2026-8612MedMay 15, 2026
    risk 0.27cvss 5.3epss 0.00

    WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constructs a default Cache::FileCache under…

  • CVE-2026-4538MedMar 22, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might…

  • CVE-2026-0895MedJan 20, 2026
    risk 0.27cvss —epss 0.00

    The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a…

  • CVE-2025-48459MedSep 24, 2025
    risk 0.27cvss 5.3epss 0.00

    Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.

  • CVE-2025-5174MedMay 26, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pypickle/pypickle.py. The manipulation leads to deserialization. Local access is required to approach this attack. The exploit has…

  • CVE-2025-5148MedMay 25, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py of the component Pickle Data Handler. The manipulation leads…

  • CVE-2023-27531MedJan 9, 2025
    risk 0.27cvss 5.3epss 0.01

    There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

  • CVE-2024-29032MedMar 20, 2024
    risk 0.27cvss 5.3epss 0.00

    Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and prior to version 0.21.2, deserializing json data using `qiskit_ibm_runtime.RuntimeDecoder` can lead…

  • CVE-2022-33900MedAug 22, 2022
    risk 0.27cvss 4.1epss 0.01

    PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.