CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 58 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-17637 | Hig | 0.57 | 8.8 | 0.00 | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data. | ||
| CVE-2025-66455 | Cri | 0.57 | 9.8 | 0.01 | Sep 18, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL… | ||
| CVE-2026-17086 | Hig | 0.57 | 8.8 | 0.01 | Sep 18, 2026 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with… | ||
| CVE-2026-20340 | Hig | 0.57 | 8.8 | 0.01 | Sep 16, 2026 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit… | ||
| CVE-2025-59953 | Cri | 0.57 | 9.8 | 0.01 | Sep 16, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core… | ||
| CVE-2026-91939 | Cri | 0.57 | 9.8 | 0.01 | Sep 15, 2026 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted… | ||
| CVE-2026-12728 | Hig | 0.57 | 8.8 | 0.00 | Sep 15, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a… | ||
| CVE-2026-13293 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system… | ||
| CVE-2026-78175 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler… | ||
| CVE-2026-62107 | Hig | 0.57 | 8.8 | 0.01 | Sep 11, 2026 | Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | ||
| CVE-2026-81385 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-77484 | Hig | 0.57 | 8.8 | 0.02 | Sep 8, 2026 | Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65772 | Hig | 0.57 | 8.8 | 0.02 | Sep 8, 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | ||
| CVE-2026-12651 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12648 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-86404 | Hig | 0.57 | 8.8 | 0.01 | Sep 7, 2026 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list… | ||
| CVE-2026-10196 | Cri | 0.57 | 9.8 | 0.01 | Sep 5, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This… | ||
| CVE-2026-84752 | Hig | 0.57 | 8.8 | 0.01 | Sep 3, 2026 | Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | ||
| CVE-2026-84670 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2026 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute… | ||
| CVE-2026-84650 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields… |
- risk 0.57cvss 8.8epss 0.00
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
- risk 0.57cvss 9.8epss 0.01
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL…
- risk 0.57cvss 8.8epss 0.01
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…
- risk 0.57cvss 8.8epss 0.01
A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit…
- risk 0.57cvss 9.8epss 0.01
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core…
- risk 0.57cvss 9.8epss 0.01
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted…
- risk 0.57cvss 8.8epss 0.00
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a…
- risk 0.57cvss 8.8epss 0.01
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system…
- risk 0.57cvss 8.8epss 0.01
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler…
- risk 0.57cvss 8.8epss 0.01
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.57cvss 8.8epss 0.01
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.57cvss 8.8epss 0.01
EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list…
- risk 0.57cvss 9.8epss 0.01
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This…
- risk 0.57cvss 8.8epss 0.01
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
- risk 0.57cvss 8.8epss 0.01
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute…
- risk 0.57cvss 8.8epss 0.00
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields…