VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 91 of 156
  • CVE-2025-14930HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14929HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required…

  • CVE-2025-14925HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in…

  • CVE-2025-14924HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2025-14922HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this…

  • CVE-2025-14921HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to…

  • CVE-2025-14920HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2025-33226HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-41700HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

  • CVE-2025-11622HigOct 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-41701HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context.

  • CVE-2025-48535HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution…

  • CVE-2025-32312HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next process due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2025-9365HigSep 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.

  • CVE-2025-7976HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu ShockLine. User interaction is required to exploit this…

  • CVE-2025-9188HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.01

    There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions…

  • CVE-2025-23303HigAug 13, 2025
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

  • CVE-2025-40759HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17…

  • CVE-2025-26397HigJul 24, 2025
    risk 0.51cvss 7.8epss 0.00

    SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires…

  • CVE-2025-30025HigJul 11, 2025
    risk 0.51cvss 7.8epss 0.00

    The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.