VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 88 of 156
  • CVE-2025-29783CriMar 19, 2025
    risk 0.52cvss 9.0epss 0.01

    vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is…

  • CVE-2024-52577CriFeb 14, 2025
    risk 0.52cvss 9.0epss 0.03

    In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in…

  • CVE-2024-49375CriJan 14, 2025
    risk 0.52cvss 9.0epss 0.01

    Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are: 1. The HTTP API…

  • CVE-2024-8514CriSep 25, 2024
    risk 0.52cvss 9.1epss 0.01

    The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers,…

  • CVE-2024-45758CriSep 6, 2024
    risk 0.52cvss 9.1epss 0.01

    H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON document containing a…

  • CVE-2024-4044HigMay 14, 2024
    risk 0.52cvss 7.8epss 0.15

    A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability…

  • CVE-2024-30229HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.

  • CVE-2024-26580CriMar 6, 2024
    risk 0.52cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or cherry-pick [1] to…

  • CVE-2024-24590HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.02

    Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

  • CVE-2023-36439HigNov 14, 2023
    risk 0.52cvss 8.0epss 0.05

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-35186HigOct 19, 2023
    risk 0.52cvss 8.0epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.

  • CVE-2023-38182HigAug 8, 2023
    risk 0.52cvss 8.0epss 0.06

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-4815HigMay 24, 2023
    risk 0.52cvss 8.0epss 0.01

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 

  • CVE-2022-28685HigMar 29, 2023
    risk 0.52cvss 7.8epss 0.17

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

  • CVE-2023-21762HigJan 10, 2023
    risk 0.52cvss 8.0epss 0.02

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-21745HigJan 10, 2023
    risk 0.52cvss 8.0epss 0.01

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2022-39256CriSep 27, 2022
    risk 0.52cvss 9.0epss 0.01

    Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated…

  • CVE-2022-22957HigApr 13, 2022
    risk 0.52cvss 7.2epss 0.23

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2020-35488HigJan 5, 2021
    risk 0.52cvss 7.5epss 0.08

    The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory…

  • CVE-2026-73325HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load…