VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 3 of 156
  • CVE-2025-24813CriKEVMar 10, 2025
    risk 0.80cvss 9.8epss 1.00

    Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2,…

  • CVE-2023-21529HigKEVFeb 14, 2023
    risk 0.80cvss 8.8epss 0.62

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2018-1000861CriKEVDec 10, 2018
    risk 0.80cvss 9.8epss 0.98

    A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs…

  • CVE-2017-1000353CriKEVJan 29, 2018
    risk 0.80cvss 9.8epss 1.00

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that…

  • CVE-2026-45247CriKEVMay 26, 2026
    risk 0.78cvss 9.8epss 0.28

    Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit…

  • CVE-2026-20963CriKEVJan 13, 2026
    risk 0.78cvss 9.8epss 0.32

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • CVE-2025-5086CriKEVJun 2, 2025
    risk 0.78cvss 9.0epss 0.90

    A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

  • CVE-2025-42999CriKEVMay 13, 2025
    risk 0.78cvss 9.1epss 0.12

    SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

  • CVE-2021-27852CriKEVMay 27, 2021
    risk 0.78cvss 9.8epss 0.32

    Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

  • CVE-2018-0824HigKEVMay 9, 2018
    risk 0.78cvss 8.8epss 0.72

    A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server…

  • CVE-2023-26359CriKEVMar 23, 2023
    risk 0.77cvss 9.8epss 0.18

    Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require…

  • CVE-2018-0147CriKEVMar 8, 2018
    risk 0.77cvss 9.8epss 0.18

    A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of…

  • CVE-2026-63077CriKEVJul 27, 2026
    risk 0.76cvss 9.8epss 0.11

    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

  • CVE-2021-26857HigKEVMar 3, 2021
    risk 0.76cvss 7.8epss 0.94

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2019-0344CriKEVAug 14, 2019
    risk 0.76cvss 9.8epss 0.07

    Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

  • CVE-2023-27372CriFeb 28, 2023
    risk 0.75cvss 9.8epss 1.00

    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

  • CVE-2021-26295CriMar 22, 2021
    risk 0.75cvss 9.8epss 0.98

    Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

  • CVE-2018-19276CriMar 21, 2019
    risk 0.75cvss 9.8epss 0.99

    OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

  • CVE-2024-5932CriAug 20, 2024
    risk 0.74cvss 10.0epss 0.74

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated…

  • CVE-2021-27850CriApr 15, 2021
    risk 0.74cvss 9.8epss 0.94

    A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before the fix of…