VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 95 of 167
  • CVE-2023-36439HigNov 14, 2023
    risk 0.52cvss 8.0epss 0.05

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-35186HigOct 19, 2023
    risk 0.52cvss 8.0epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.

  • CVE-2023-38182HigAug 8, 2023
    risk 0.52cvss 8.0epss 0.06

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-4815HigMay 24, 2023
    risk 0.52cvss 8.0epss 0.01

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 

  • CVE-2022-28685HigMar 29, 2023
    risk 0.52cvss 7.8epss 0.17

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

  • CVE-2023-21762HigJan 10, 2023
    risk 0.52cvss 8.0epss 0.02

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-21745HigJan 10, 2023
    risk 0.52cvss 8.0epss 0.01

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2022-39256CriSep 27, 2022
    risk 0.52cvss 9.0epss 0.02

    Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated…

  • CVE-2022-22957HigApr 13, 2022
    risk 0.52cvss 7.2epss 0.24

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2020-35488HigJan 5, 2021
    risk 0.52cvss 7.5epss 0.08

    The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory…

  • CVE-2020-26207HigNov 4, 2020
    risk 0.52cvss 8.0epss 0.02

    DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

  • CVE-2026-24267HigSep 22, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…

  • CVE-2026-24239HigSep 22, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

  • CVE-2026-17416HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

  • CVE-2026-17156HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

  • CVE-2026-76967HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next…

  • CVE-2026-76843HigAug 24, 2026
    risk 0.51cvss 7.8epss 0.00

    The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an…

  • CVE-2026-49817HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-49816HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-60412HigAug 18, 2026
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle…