VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 49 of 156
  • CVE-2025-54897HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.19

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-47579CriSep 9, 2025
    risk 0.59cvss 9.0epss 0.00

    Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.

  • CVE-2025-53772HigAug 12, 2025
    risk 0.59cvss 8.8epss 0.22

    Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

  • CVE-2025-49712HigAug 12, 2025
    risk 0.59cvss 8.8epss 0.18

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-30023CriJul 11, 2025
    risk 0.59cvss 9.0epss 0.01

    The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

  • CVE-2025-42980CriJul 8, 2025
    risk 0.59cvss 9.1epss 0.01

    SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

  • CVE-2025-42966CriJul 8, 2025
    risk 0.59cvss 9.1epss 0.01

    SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact on confidentiality, integrity,…

  • CVE-2025-42964CriJul 8, 2025
    risk 0.59cvss 9.1epss 0.01

    SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

  • CVE-2025-42963CriJul 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control…

  • CVE-2025-36038CriJun 25, 2025
    risk 0.59cvss 9.0epss 0.09

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

  • CVE-2025-24447CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation…

  • CVE-2025-26873CriMar 27, 2025
    risk 0.59cvss 9.0epss 0.00

    Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

  • CVE-2025-23120HigMar 20, 2025
    risk 0.59cvss 8.8epss 0.22

    A vulnerability allowing remote code execution (RCE) for domain users.

  • CVE-2024-57766CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.01

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

  • CVE-2024-57764CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.01

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.

  • CVE-2024-57763CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.01

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.

  • CVE-2024-52046CriDec 25, 2024
    risk 0.59cvss 9.8epss 0.24

    The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process by sending specially…

  • CVE-2024-37285CriNov 14, 2024
    risk 0.59cvss 9.1epss 0.01

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges…

  • CVE-2024-28991CriSep 12, 2024
    risk 0.59cvss 9.0epss 0.03

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

  • CVE-2024-8016CriAug 30, 2024
    risk 0.59cvss 9.1epss 0.01

    The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with…