CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 89 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40751 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. | ||
| CVE-2026-40739 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions. | ||
| CVE-2026-40736 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions. | ||
| CVE-2026-40735 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reina <= 2.1 versions. | ||
| CVE-2026-39580 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions. | ||
| CVE-2026-39573 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions. | ||
| CVE-2026-39567 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions. | ||
| CVE-2026-39557 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions. | ||
| CVE-2026-39554 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions. | ||
| CVE-2026-39545 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions. | ||
| CVE-2026-39539 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. | ||
| CVE-2026-39446 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. | ||
| CVE-2026-39443 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. | ||
| CVE-2026-48853 | Cri | 0.53 | — | 0.01 | Jun 15, 2026 | Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it,… | ||
| CVE-2026-42687 | Hig | 0.53 | 8.1 | 0.00 | Jun 15, 2026 | Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. | ||
| CVE-2026-27333 | Hig | 0.53 | 8.1 | 0.00 | Jun 15, 2026 | Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions. | ||
| CVE-2026-41732 | Hig | 0.53 | 8.1 | 0.00 | Jun 10, 2026 | JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a… | ||
| CVE-2026-39555 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1. | ||
| CVE-2026-39551 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1. | ||
| CVE-2026-39550 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6. |
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
- risk 0.53cvss —epss 0.01
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it,…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
- risk 0.53cvss 8.1epss 0.00
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a…
- risk 0.53cvss 8.1epss 0.00
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.
- risk 0.53cvss 8.1epss 0.00
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.
- risk 0.53cvss 8.1epss 0.00
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.