VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 162 of 167
  • CVE-2026-54469HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.01

    Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

  • CVE-2026-59827CriJul 9, 2026
    risk 0.00cvss 9.9epss 0.04

    Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native…

  • CVE-2026-14723MedJul 5, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed…

  • CVE-2026-57677CriJul 2, 2026
    risk 0.00cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

  • CVE-2026-57621CriJul 2, 2026
    risk 0.00cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

  • CVE-2026-56037HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

  • CVE-2026-27414HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.01

    Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

  • CVE-2026-27060HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium: from n/a before 7.6.

  • CVE-2026-51947CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this…

  • CVE-2026-58127CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.02

    PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and…

  • CVE-2026-58126CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.02

    PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication…

  • CVE-2026-24251HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information…

  • CVE-2026-24250HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24247HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24245HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24244HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24243HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24240HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-10538HigJul 1, 2026
    risk 0.00cvss 8.0epss 0.00

    Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an…

  • CVE-2026-56700CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.03

    Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection…