VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 161 of 167
  • CVE-2026-47472HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and…

  • CVE-2026-24233HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code…

  • CVE-2026-24227MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-55944CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.02

    Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

  • CVE-2026-50509HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.04

    Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55009HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50652HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.02

    Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

  • CVE-2026-12583HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…

  • CVE-2026-58233HigJul 14, 2026
    risk 0.00cvss 7.6epss 0.01

    SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system.…

  • CVE-2026-59521HigJul 13, 2026
    risk 0.00cvss 7.2epss 0.01

    Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

  • CVE-2026-59518CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

  • CVE-2026-57770CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

  • CVE-2026-57744CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

  • CVE-2026-57738CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

  • CVE-2026-57724CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

  • CVE-2026-57713HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

  • CVE-2026-57371HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

  • CVE-2026-15535MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument…

  • CVE-2026-15531MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to…

  • CVE-2026-58281HigJul 11, 2026
    risk 0.00cvss 8.3epss 0.01

    Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.