VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 81 of 156
  • CVE-2023-40555HigDec 20, 2023
    risk 0.54cvss 8.3epss 0.00

    Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.

  • CVE-2023-34027HigDec 19, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Viewed Products: from n/a through 1.0.0.

  • CVE-2023-37390HigDec 19, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.

  • CVE-2023-35180HigOct 19, 2023
    risk 0.54cvss 8.0epss 0.27

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse SolarWinds ARM API.

  • CVE-2023-28310HigJun 14, 2023
    risk 0.54cvss 8.0epss 0.25

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-38111HigFeb 15, 2023
    risk 0.54cvss 7.2epss 0.85

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-41966HigDec 28, 2022
    risk 0.54cvss 8.2epss 0.09

    XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code…

  • CVE-2022-35870HigJul 25, 2022
    risk 0.54cvss 7.8epss 0.43

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2021-26913HigFeb 8, 2021
    risk 0.54cvss 8.1epss 0.13

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.

  • CVE-2019-17080HigOct 2, 2019
    risk 0.54cvss 7.8epss 0.08

    mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.

  • CVE-2018-16364HigSep 26, 2018
    risk 0.54cvss 8.1epss 0.18

    A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.

  • CVE-2017-7293HigApr 26, 2017
    risk 0.54cvss 7.8epss 0.03

    The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1,…

  • CVE-2026-16267HigAug 8, 2026
    risk 0.53cvss 8.1epss 0.00

    The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

  • CVE-2026-47623HigAug 4, 2026
    risk 0.53cvss 8.2epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-14974HigJul 28, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

  • CVE-2026-13190HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.

  • CVE-2026-13185HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.

  • CVE-2026-39253HigJun 23, 2026
    risk 0.53cvss 8.1epss 0.01

    An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.

  • CVE-2026-45034CriJun 22, 2026
    risk 0.53cvss epss 0.00

    PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to…

  • CVE-2025-71378HigJun 21, 2026
    risk 0.53cvss 8.1epss 0.00

    picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().