VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 58 of 167
  • CVE-2026-17637HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

  • CVE-2025-66455CriSep 18, 2026
    risk 0.57cvss 9.8epss 0.01

    LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL…

  • CVE-2026-17086HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.01

    The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…

  • CVE-2026-20340HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit…

  • CVE-2025-59953CriSep 16, 2026
    risk 0.57cvss 9.8epss 0.01

    LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core…

  • CVE-2026-91939CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted…

  • CVE-2026-12728HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a…

  • CVE-2026-13293HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system…

  • CVE-2026-78175HigSep 12, 2026
    risk 0.57cvss 8.8epss 0.01

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler…

  • CVE-2026-62107HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

  • CVE-2026-81385HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

  • CVE-2026-77484HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

  • CVE-2026-65772HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

  • CVE-2026-12651HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12648HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-86404HigSep 7, 2026
    risk 0.57cvss 8.8epss 0.01

    EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list…

  • CVE-2026-10196CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This…

  • CVE-2026-84752HigSep 3, 2026
    risk 0.57cvss 8.8epss 0.01

    Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

  • CVE-2026-84670HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.01

    Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute…

  • CVE-2026-84650HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields…