VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 53 of 167
  • CVE-2025-24447CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation…

  • CVE-2025-26873CriMar 27, 2025
    risk 0.59cvss 9.0epss 0.00

    Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

  • CVE-2025-23120HigMar 20, 2025
    risk 0.59cvss 8.8epss 0.24

    A vulnerability allowing remote code execution (RCE) for domain users.

  • CVE-2024-57766CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.01

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

  • CVE-2024-57764CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.01

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.

  • CVE-2024-57763CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.01

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.

  • CVE-2024-52046CriDec 25, 2024
    risk 0.59cvss 9.8epss 0.24

    The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process by sending specially…

  • CVE-2024-37285CriNov 14, 2024
    risk 0.59cvss 9.1epss 0.01

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges…

  • CVE-2024-28991CriSep 12, 2024
    risk 0.59cvss 9.0epss 0.03

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

  • CVE-2024-8016CriAug 30, 2024
    risk 0.59cvss 9.1epss 0.01

    The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with…

  • CVE-2024-43252CriAug 19, 2024
    risk 0.59cvss 9.0epss 0.00

    Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

  • CVE-2024-43242CriAug 19, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

  • CVE-2024-4371CriJun 13, 2024
    risk 0.59cvss 9.0epss 0.01

    The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products…

  • CVE-2024-3300CriMay 30, 2024
    risk 0.59cvss 9.0epss 0.03

    An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

  • CVE-2024-27322HigApr 29, 2024
    risk 0.59cvss 8.8epss 0.23

    Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s…

  • CVE-2024-33553CriApr 29, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

  • CVE-2024-30227CriMar 28, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.

  • CVE-2024-30226CriMar 28, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.

  • CVE-2024-30223CriMar 28, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

  • CVE-2024-23478HigFeb 15, 2024
    risk 0.59cvss 8.0epss 0.82

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution.