VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 163 of 166
  • CVE-2024-47092CriMar 3, 2025
    risk 0.00cvss 9.8epss 0.00

    Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

  • CVE-2025-23045CriJan 28, 2025
    risk 0.00cvss 9.8epss 0.01

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT…

  • CVE-2024-54136CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/upload.php where the user supplied input via collection get parameter is directly…

  • CVE-2024-54135CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/photo_upload.php within the decode_key function. User inputs were supplied…

  • CVE-2024-47074CriOct 11, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataease/provider/datasource/JdbcPro…

  • CVE-2024-42362HigAug 20, 2024
    risk 0.00cvss 8.8epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.

  • CVE-2024-8003LowAug 20, 2024
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log Handler. The manipulation leads to deserialization. The patch is identified as…

  • CVE-2024-7067MedJul 24, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of the file app/Cart.php. The manipulation of the argument laraCart leads…

  • CVE-2024-31224CriApr 8, 2024
    risk 0.00cvss 9.8epss 0.01

    GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution. Any device that exposes the GPT…

  • CVE-2024-28861CriMar 22, 2024
    risk 0.00cvss 9.8epss 0.02

    Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget chain due to dangerous deserialization in `sfNamespacedParameterHolder` class that would enable an…

  • CVE-2024-23328CriFeb 29, 2024
    risk 0.00cvss 9.1epss 0.01

    Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type…

  • CVE-2023-51389CriFeb 22, 2024
    risk 0.00cvss 9.8epss 0.01

    Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration is used, resulting in a YAML deserialization vulnerability. Version 1.4.1 fixes this vulnerability.

  • CVE-2023-51700MedDec 27, 2023
    risk 0.00cvss 6.4epss 0.01

    Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,…

  • CVE-2023-44392HigOct 9, 2023
    risk 0.00cvss 8.2epss 0.01

    Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library, which is vulnerable to code injection due to an insecure implementation of deserialization. Garden stores serialized objects…

  • CVE-2023-38689HigAug 4, 2023
    risk 0.00cvss 8.1epss 0.01

    Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `ObjectInputStream#readObject` on untrusted data coming from clients or servers over the network resulting in possible remote code execution when sending specifically…

  • CVE-2023-29006HigApr 5, 2023
    risk 0.00cvss 8.8epss 0.01

    The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions…

  • CVE-2023-26234MedFeb 21, 2023
    risk 0.00cvss 6.6epss 0.01

    JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.

  • CVE-2023-25558HigFeb 11, 2023
    risk 0.00cvss 7.5epss 0.01

    DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The processing of the `id_token` is done in an unsafe manner which is not properly accounted for by the DataHub frontend.…

  • CVE-2022-4890MedJan 16, 2023
    risk 0.00cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The…

  • CVE-2022-41958HigNov 25, 2022
    risk 0.00cvss 7.3epss 0.00

    super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit…