VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 158 of 167
  • CVE-2023-35815LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.01

    DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

  • CVE-2023-35814LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.01

    DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

  • CVE-2026-5473MedApr 3, 2026
    risk 0.22cvss 4.5epss 0.00

    A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The…

  • CVE-2024-27281MedMay 14, 2024
    risk 0.22cvss 4.5epss 0.02

    An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the…

  • CVE-2023-34382MedDec 19, 2023
    risk 0.22cvss 4.4epss 0.01

    Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from…

  • CVE-2022-29615LowJun 14, 2022
    risk 0.22cvss 3.4epss 0.00

    SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.

  • CVE-2019-16774MedDec 12, 2019
    risk 0.22cvss 4.4epss 0.01

    In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.

  • CVE-2019-12760LowJun 6, 2019
    risk 0.22cvss 3.3epss 0.02

    A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to…

  • CVE-2023-3360LowSep 2, 2026
    risk 0.21cvss 3.3epss 0.00

    The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2026-44501MedMay 14, 2026
    risk 0.21cvss 4.3epss 0.00

    DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This…

  • CVE-2024-29040MedJun 28, 2024
    risk 0.21cvss 4.3epss 0.00

    This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this…

  • CVE-2026-59306LowAug 27, 2026
    risk 0.20cvss 3.1epss 0.00

    Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

  • CVE-2025-15117LowDec 28, 2025
    risk 0.20cvss 3.1epss 0.00

    A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer.java. Executing manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high…

  • CVE-2025-10252LowSep 11, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high…

  • CVE-2016-0750MedSep 11, 2018
    risk 0.20cvss 4.2epss 0.02

    The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

  • CVE-2026-10532LowJun 1, 2026
    risk 0.19cvss —epss 0.00

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer…

  • CVE-2026-9828LowMay 28, 2026
    risk 0.19cvss —epss 0.01

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or…

  • CVE-2026-5507MedApr 9, 2026
    risk 0.19cvss 4.0epss 0.00

    When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the…

  • CVE-2026-50522CriKEVJul 14, 2026
    risk 0.18cvss 9.8epss 0.03

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • CVE-2024-6525LowJul 5, 2024
    risk 0.18cvss 2.7epss 0.03

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The…