VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 50 of 167
  • CVE-2026-26220CriFeb 17, 2026
    risk 0.61cvss —epss 0.02

    LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without…

  • CVE-2026-26215CriFeb 11, 2026
    risk 0.61cvss —epss 0.01

    manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled…

  • CVE-2026-23746CriJan 15, 2026
    risk 0.61cvss —epss 0.01

    Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service…

  • CVE-2025-34414CriDec 9, 2025
    risk 0.61cvss —epss 0.01

    Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP…

  • CVE-2025-47166HigJun 10, 2025
    risk 0.61cvss 8.8epss 0.21

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2024-49147CriDec 12, 2024
    risk 0.61cvss 9.3epss 0.01

    Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

  • CVE-2024-38018HigSep 10, 2024
    risk 0.61cvss 8.8epss 0.51

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-34668CriAug 29, 2022
    risk 0.61cvss 9.8epss 0.11

    NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

  • CVE-2022-23307HigJan 18, 2022
    risk 0.61cvss 8.8epss 0.54

    CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

  • CVE-2021-24040CriSep 10, 2021
    risk 0.61cvss 9.8epss 0.17

    Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

  • CVE-2021-31010HigKEVAug 24, 2021
    risk 0.61cvss 7.5epss 0.04

    A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was…

  • CVE-2021-24307HigMay 24, 2021
    risk 0.61cvss 8.8epss 0.53

    The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's…

  • CVE-2019-16112HigMay 13, 2020
    risk 0.61cvss 8.8epss 0.11

    TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.

  • CVE-2019-11080HigJun 6, 2019
    risk 0.61cvss 8.8epss 0.14

    Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.

  • CVE-2019-9055HigMar 26, 2019
    risk 0.61cvss 8.8epss 0.12

    An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the…

  • CVE-2018-20221HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.10

    Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.

  • CVE-2017-17485CriJan 10, 2018
    risk 0.61cvss 9.8epss 0.50

    FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the…

  • CVE-2016-7065HigOct 13, 2016
    risk 0.61cvss 8.8epss 0.12

    The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.

  • CVE-2026-51106CriAug 26, 2026
    risk 0.60cvss 9.3epss 0.00

    An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component

  • CVE-2026-80428CriAug 26, 2026
    risk 0.60cvss 9.8epss 0.05

    ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via…