VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 80 of 156
  • CVE-2024-1856HigMar 20, 2024
    risk 0.55cvss 8.5epss 0.01

    In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.

  • CVE-2024-29136HigMar 19, 2024
    risk 0.55cvss 8.5epss 0.01

    Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.

  • CVE-2023-36050HigNov 14, 2023
    risk 0.55cvss 8.0epss 0.39

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-42809CriOct 4, 2023
    risk 0.55cvss 9.6epss 0.01

    Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client deserializes without further validation. Attackers that manage to trick clients into communicating…

  • CVE-2023-36825CriJul 11, 2023
    risk 0.55cvss 9.6epss 0.01

    Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deserialization of untrusted data from the…

  • CVE-2023-2141HigApr 21, 2023
    risk 0.55cvss 8.5epss 0.01

    An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

  • CVE-2022-38108HigOct 20, 2022
    risk 0.55cvss 7.2epss 0.68

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2021-35095HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-4104HigDec 14, 2021
    risk 0.55cvss 7.5epss 0.81

    JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests…

  • CVE-2021-21341HigMar 23, 2021
    risk 0.55cvss 7.5epss 0.78

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting…

  • CVE-2018-1000888HigDec 28, 2018
    risk 0.55cvss 8.8epss 0.19

    PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific…

  • CVE-2026-33454CriApr 27, 2026
    risk 0.54cvss 9.4epss 0.01

    The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via…

  • CVE-2025-34292CriOct 27, 2025
    risk 0.54cvss epss 0.01

    Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in \\RoxPostHandler::getCallbackAction and…

  • CVE-2025-48951CriJun 3, 2025
    risk 0.54cvss epss 0.01

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could…

  • CVE-2024-55555HigJan 7, 2025
    risk 0.54cvss 8.8epss 0.07

    Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the…

  • CVE-2024-11392HigNov 22, 2024
    risk 0.54cvss 8.8epss 0.07

    Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2024-39636HigAug 1, 2024
    risk 0.54cvss 8.3epss 0.00

    Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.

  • CVE-2024-30044HigMay 14, 2024
    risk 0.54cvss 7.2epss 0.84

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-32600HigApr 18, 2024
    risk 0.54cvss 8.3epss 0.00

    Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.

  • CVE-2023-28782HigDec 20, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.