VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 87 of 167
  • CVE-2024-30044HigMay 14, 2024
    risk 0.54cvss 7.2epss 0.84

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-32600HigApr 18, 2024
    risk 0.54cvss 8.3epss 0.00

    Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.

  • CVE-2023-28782HigDec 20, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.

  • CVE-2023-40555HigDec 20, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.

  • CVE-2023-34027HigDec 19, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Viewed Products: from n/a through 1.0.0.

  • CVE-2023-37390HigDec 19, 2023
    risk 0.54cvss 8.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.

  • CVE-2023-35180HigOct 19, 2023
    risk 0.54cvss 8.0epss 0.27

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse SolarWinds ARM API.

  • CVE-2023-28310HigJun 14, 2023
    risk 0.54cvss 8.0epss 0.25

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-38111HigFeb 15, 2023
    risk 0.54cvss 7.2epss 0.85

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-41966HigDec 28, 2022
    risk 0.54cvss 8.2epss 0.09

    XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code…

  • CVE-2022-35870HigJul 25, 2022
    risk 0.54cvss 7.8epss 0.43

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2021-26913HigFeb 8, 2021
    risk 0.54cvss 8.1epss 0.13

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.

  • CVE-2019-17080HigOct 2, 2019
    risk 0.54cvss 7.8epss 0.08

    mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.

  • CVE-2018-16364HigSep 26, 2018
    risk 0.54cvss 8.1epss 0.18

    A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.

  • CVE-2017-7293HigApr 26, 2017
    risk 0.54cvss 7.8epss 0.03

    The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1,…

  • CVE-2026-46495CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive…

  • CVE-2026-62263CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A…

  • CVE-2026-45051CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the…

  • CVE-2026-84099HigSep 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be…

  • CVE-2026-81784HigSep 10, 2026
    risk 0.53cvss 8.1epss 0.00

    Deserialization of Untrusted Data vulnerability in Marcin Wise Chat wise-chat allows Object Injection.This issue affects Wise Chat: from n/a through 3.4.2.