VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 92 of 156
  • CVE-2025-47994HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.03

    Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-53416HigJun 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

  • CVE-2025-53415HigJun 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

  • CVE-2025-49127HigJun 6, 2025
    risk 0.51cvss epss 0.00

    Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.

  • CVE-2025-30382HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-34489HigApr 28, 2025
    risk 0.51cvss 7.8epss 0.00

    GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service.

  • CVE-2024-12742HigMar 6, 2025
    risk 0.51cvss 7.8epss 0.06

    A deserialization of untrusted data vulnerability exists in NI G Web Development Software that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted project file.  This vulnerability affects G Web…

  • CVE-2024-12703HigJan 17, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when a non-admin authenticated user opens a malicious project file.

  • CVE-2025-21364HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Microsoft Excel Security Feature Bypass Vulnerability

  • CVE-2024-13163HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.09

    Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2024-12677HigDec 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

  • CVE-2024-12741HigDec 18, 2024
    risk 0.51cvss 7.8epss 0.04

    A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions.…

  • CVE-2024-49849HigDec 10, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety…

  • CVE-2018-9474HigNov 20, 2024
    risk 0.51cvss 7.8epss 0.00

    In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43080HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-10013HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-10012HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-8316HigSep 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-7576HigSep 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-42323HigSep 21, 2024
    risk 0.51cvss 8.8epss 0.08

    SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which…