CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 95 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36439 | Hig | 0.52 | 8.0 | 0.05 | Nov 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-35186 | Hig | 0.52 | 8.0 | 0.02 | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. | ||
| CVE-2023-38182 | Hig | 0.52 | 8.0 | 0.06 | Aug 8, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-4815 | Hig | 0.52 | 8.0 | 0.01 | May 24, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. | ||
| CVE-2022-28685 | Hig | 0.52 | 7.8 | 0.17 | Mar 29, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.… | ||
| CVE-2023-21762 | Hig | 0.52 | 8.0 | 0.02 | Jan 10, 2023 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2023-21745 | Hig | 0.52 | 8.0 | 0.01 | Jan 10, 2023 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2022-39256 | Cri | 0.52 | 9.0 | 0.02 | Sep 27, 2022 | Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated… | ||
| CVE-2022-22957 | Hig | 0.52 | 7.2 | 0.24 | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which… | ||
| CVE-2020-35488 | Hig | 0.52 | 7.5 | 0.08 | Jan 5, 2021 | The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory… | ||
| CVE-2020-26207 | Hig | 0.52 | 8.0 | 0.02 | Nov 4, 2020 | DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened. | ||
| CVE-2026-24267 | Hig | 0.51 | 7.8 | 0.00 | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,… | ||
| CVE-2026-24239 | Hig | 0.51 | 7.8 | 0.00 | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | ||
| CVE-2026-17416 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | ||
| CVE-2026-17156 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | ||
| CVE-2026-76967 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next… | ||
| CVE-2026-76843 | Hig | 0.51 | 7.8 | 0.00 | Aug 24, 2026 | The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an… | ||
| CVE-2026-49817 | Hig | 0.51 | 7.8 | 0.00 | Aug 19, 2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||
| CVE-2026-49816 | Hig | 0.51 | 7.8 | 0.00 | Aug 19, 2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||
| CVE-2026-60412 | Hig | 0.51 | 7.8 | 0.00 | Aug 18, 2026 | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… |
- risk 0.52cvss 8.0epss 0.05
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.52cvss 8.0epss 0.02
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.
- risk 0.52cvss 8.0epss 0.06
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.52cvss 8.0epss 0.01
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
- risk 0.52cvss 7.8epss 0.17
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…
- risk 0.52cvss 8.0epss 0.02
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.01
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.52cvss 9.0epss 0.02
Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated…
- risk 0.52cvss 7.2epss 0.24
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…
- risk 0.52cvss 7.5epss 0.08
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory…
- risk 0.52cvss 8.0epss 0.02
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.
- risk 0.51cvss 7.8epss 0.00
NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…
- risk 0.51cvss 7.8epss 0.00
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
- risk 0.51cvss 7.8epss 0.00
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.
- risk 0.51cvss 7.8epss 0.00
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.
- risk 0.51cvss 7.8epss 0.00
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next…
- risk 0.51cvss 7.8epss 0.00
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an…
- risk 0.51cvss 7.8epss 0.00
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- risk 0.51cvss 7.8epss 0.00
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- risk 0.51cvss 7.8epss 0.00
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle…