CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 82 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-71357 | Hig | 0.53 | 8.1 | 0.00 | Jun 21, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. | ||
| CVE-2025-71348 | Hig | 0.53 | 8.1 | 0.00 | Jun 21, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote… | ||
| CVE-2026-40761 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. | ||
| CVE-2026-40760 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Behold <= 1.5 versions. | ||
| CVE-2026-40759 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Esmée <= 1.4 versions. | ||
| CVE-2026-40758 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. | ||
| CVE-2026-40755 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in TechLink <= 1.3 versions. | ||
| CVE-2026-40754 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. | ||
| CVE-2026-40753 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. | ||
| CVE-2026-40751 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. | ||
| CVE-2026-40739 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions. | ||
| CVE-2026-40736 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions. | ||
| CVE-2026-40735 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reina <= 2.1 versions. | ||
| CVE-2026-39580 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions. | ||
| CVE-2026-39573 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions. | ||
| CVE-2026-39567 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions. | ||
| CVE-2026-39557 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions. | ||
| CVE-2026-39554 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions. | ||
| CVE-2026-39545 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions. | ||
| CVE-2026-39539 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. |
- risk 0.53cvss 8.1epss 0.00
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
- risk 0.53cvss 8.1epss 0.00
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.