VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 89 of 156
  • CVE-2026-24228HigJun 16, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-12191HigJun 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The…

  • CVE-2026-25551HigJun 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe,…

  • CVE-2026-24237HigJun 2, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-24221HigJun 2, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.

  • CVE-2026-24162HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-24216HigMay 20, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

  • CVE-2026-7584HigMay 1, 2026
    risk 0.51cvss 7.8epss 0.00

    The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names from the serialized data without any…

  • CVE-2026-32192HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.02

    Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2026-32184HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.02

    Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24165HigMar 31, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

  • CVE-2026-4416HigMar 30, 2026
    risk 0.51cvss 7.8epss 0.00

    The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.

  • CVE-2026-24159HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.

  • CVE-2026-24157HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.

  • CVE-2026-24152HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure,…

  • CVE-2026-24151HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously crafted input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and…

  • CVE-2026-24150HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure,…

  • CVE-2026-24141HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A successful exploit of this vulnerability might lead to code execution,…

  • CVE-2025-33248HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information…

  • CVE-2025-33247HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.