VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 79 of 156
  • CVE-2026-12578HigJun 30, 2026
    risk 0.55cvss epss 0.00

    The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.

  • CVE-2026-11857HigJun 17, 2026
    risk 0.55cvss epss 0.00

    Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel.Full and is bound to local interfaces only through named…

  • CVE-2026-7888HigJun 3, 2026
    risk 0.55cvss epss 0.00

    Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious…

  • CVE-2026-9330HigJun 1, 2026
    risk 0.55cvss 8.5epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable…

  • CVE-2026-3071HigFeb 26, 2026
    risk 0.55cvss 8.4epss 0.00

    Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

  • CVE-2025-70560HigFeb 3, 2026
    risk 0.55cvss 8.4epss 0.00

    Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed…

  • CVE-2025-61810HigDec 10, 2025
    risk 0.55cvss 8.4epss 0.09

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing…

  • CVE-2025-47584HigJun 6, 2025
    risk 0.55cvss 8.5epss 0.00

    Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.

  • CVE-2025-47292CriMay 14, 2025
    risk 0.55cvss epss 0.01

    Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by unauthenticated user.…

  • CVE-2025-30284HigApr 8, 2025
    risk 0.55cvss 8.4epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-31175HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2025-27925HigMar 10, 2025
    risk 0.55cvss 8.5epss 0.00

    Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

  • CVE-2024-10095HigDec 16, 2024
    risk 0.55cvss 8.4epss 0.01

    In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-49063HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.02

    Microsoft/Muzic Remote Code Execution Vulnerability

  • CVE-2024-3468HigJun 12, 2024
    risk 0.55cvss epss 0.00

    There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.

  • CVE-2024-33568HigJun 4, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a before 7.19.3.

  • CVE-2024-3301HigMay 30, 2024
    risk 0.55cvss 8.5epss 0.01

    An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.

  • CVE-2024-32603HigApr 18, 2024
    risk 0.55cvss 8.5epss 0.01

    Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.

  • CVE-2024-31094HigMar 31, 2024
    risk 0.55cvss 8.5epss 0.01

    Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.

  • CVE-2024-30222HigMar 28, 2024
    risk 0.55cvss 8.5epss 0.01

    Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.