CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 161 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-47472 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and… | ||
| CVE-2026-24233 | Hig | 0.00 | 8.4 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code… | ||
| CVE-2026-24227 | Med | 0.00 | 5.3 | 0.01 | Jul 14, 2026 | NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution. | ||
| CVE-2026-55944 | Cri | 0.00 | 9.8 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-50509 | Hig | 0.00 | 7.8 | 0.04 | Jul 14, 2026 | Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55009 | Hig | 0.00 | 7.8 | 0.03 | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50652 | Hig | 0.00 | 7.5 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-12583 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress… | ||
| CVE-2026-58233 | Hig | 0.00 | 7.6 | 0.01 | Jul 14, 2026 | SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system.… | ||
| CVE-2026-59521 | Hig | 0.00 | 7.2 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | ||
| CVE-2026-59518 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | ||
| CVE-2026-57770 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8. | ||
| CVE-2026-57744 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. | ||
| CVE-2026-57738 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0. | ||
| CVE-2026-57724 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. | ||
| CVE-2026-57713 | Hig | 0.00 | 8.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6. | ||
| CVE-2026-57371 | Hig | 0.00 | 8.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0. | ||
| CVE-2026-15535 | Med | 0.00 | 6.3 | 0.00 | Jul 13, 2026 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument… | ||
| CVE-2026-15531 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to… | ||
| CVE-2026-58281 | Hig | 0.00 | 8.3 | 0.01 | Jul 11, 2026 | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
- risk 0.00cvss 7.8epss 0.00
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and…
- risk 0.00cvss 8.4epss 0.00
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code…
- risk 0.00cvss 5.3epss 0.01
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
- risk 0.00cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.8epss 0.04
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.03
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.5epss 0.02
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 8.1epss 0.01
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…
- risk 0.00cvss 7.6epss 0.01
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system.…
- risk 0.00cvss 7.2epss 0.01
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- risk 0.00cvss 8.8epss 0.00
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
- risk 0.00cvss 8.8epss 0.01
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
- risk 0.00cvss 6.3epss 0.00
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument…
- risk 0.00cvss 5.3epss 0.00
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to…
- risk 0.00cvss 8.3epss 0.01
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.