VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 160 of 167
  • CVE-2026-65617HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.01

    A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

  • CVE-2026-15962HigJul 26, 2026
    risk 0.00cvss 8.8epss 0.01

    The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a…

  • CVE-2026-50517CriJul 24, 2026
    risk 0.00cvss 9.9epss 0.02

    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

  • CVE-2026-65497HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.01

    Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

  • CVE-2026-65493HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

  • CVE-2026-59544CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

  • CVE-2026-16723CriJul 23, 2026
    risk 0.00cvss 9.0epss 0.01

    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

  • CVE-2026-61246HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60439HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60373HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60372CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.01

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-60369CriJul 22, 2026
    risk 0.00cvss 9.9epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60367CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.01

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-60366CriJul 22, 2026
    risk 0.00cvss 10.0epss 0.01

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-24232MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-64606CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version…

  • CVE-2026-63767CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces.…

  • CVE-2026-28220HigJul 20, 2026
    risk 0.00cvss 8.4epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster…

  • CVE-2026-8476CriJul 17, 2026
    risk 0.00cvss 9.9epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity…

  • CVE-2026-15008HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.01

    The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it…