CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 79 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12578 | Hig | 0.55 | — | 0.00 | Jun 30, 2026 | The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code. | ||
| CVE-2026-11857 | Hig | 0.55 | — | 0.00 | Jun 17, 2026 | Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel.Full and is bound to local interfaces only through named… | ||
| CVE-2026-7888 | Hig | 0.55 | — | 0.00 | Jun 3, 2026 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious… | ||
| CVE-2026-9330 | Hig | 0.55 | 8.5 | 0.01 | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable… | ||
| CVE-2026-3071 | Hig | 0.55 | 8.4 | 0.00 | Feb 26, 2026 | Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model. | ||
| CVE-2025-70560 | Hig | 0.55 | 8.4 | 0.00 | Feb 3, 2026 | Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed… | ||
| CVE-2025-61810 | Hig | 0.55 | 8.4 | 0.09 | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing… | ||
| CVE-2025-47584 | Hig | 0.55 | 8.5 | 0.00 | Jun 6, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2. | ||
| CVE-2025-47292 | Cri | 0.55 | — | 0.01 | May 14, 2025 | Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by unauthenticated user.… | ||
| CVE-2025-30284 | Hig | 0.55 | 8.4 | 0.02 | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass… | ||
| CVE-2025-31175 | Hig | 0.55 | 8.4 | 0.00 | Apr 7, 2025 | Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2025-27925 | Hig | 0.55 | 8.5 | 0.00 | Mar 10, 2025 | Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. | ||
| CVE-2024-10095 | Hig | 0.55 | 8.4 | 0.01 | Dec 16, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability. | ||
| CVE-2024-49063 | Hig | 0.55 | 8.4 | 0.02 | Dec 12, 2024 | Microsoft/Muzic Remote Code Execution Vulnerability | ||
| CVE-2024-3468 | Hig | 0.55 | — | 0.00 | Jun 12, 2024 | There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker. | ||
| CVE-2024-33568 | Hig | 0.55 | 8.5 | 0.01 | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a before 7.19.3. | ||
| CVE-2024-3301 | Hig | 0.55 | 8.5 | 0.01 | May 30, 2024 | An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution. | ||
| CVE-2024-32603 | Hig | 0.55 | 8.5 | 0.01 | Apr 18, 2024 | Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20. | ||
| CVE-2024-31094 | Hig | 0.55 | 8.5 | 0.01 | Mar 31, 2024 | Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | ||
| CVE-2024-30222 | Hig | 0.55 | 8.5 | 0.01 | Mar 28, 2024 | Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26. |
- risk 0.55cvss —epss 0.00
The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.
- risk 0.55cvss —epss 0.00
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel.Full and is bound to local interfaces only through named…
- risk 0.55cvss —epss 0.00
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious…
- risk 0.55cvss 8.5epss 0.01
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable…
- risk 0.55cvss 8.4epss 0.00
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.
- risk 0.55cvss 8.4epss 0.00
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed…
- risk 0.55cvss 8.4epss 0.09
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing…
- risk 0.55cvss 8.5epss 0.00
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.
- risk 0.55cvss —epss 0.01
Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by unauthenticated user.…
- risk 0.55cvss 8.4epss 0.02
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…
- risk 0.55cvss 8.4epss 0.00
Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.
- risk 0.55cvss 8.5epss 0.00
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
- risk 0.55cvss 8.4epss 0.01
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
- risk 0.55cvss 8.4epss 0.02
Microsoft/Muzic Remote Code Execution Vulnerability
- risk 0.55cvss —epss 0.00
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
- risk 0.55cvss 8.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a before 7.19.3.
- risk 0.55cvss 8.5epss 0.01
An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.
- risk 0.55cvss 8.5epss 0.01
Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.
- risk 0.55cvss 8.5epss 0.01
Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
- risk 0.55cvss 8.5epss 0.01
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.