VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 97 of 167
  • CVE-2026-24141HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A successful exploit of this vulnerability might lead to code execution,…

  • CVE-2025-33248HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information…

  • CVE-2025-33247HigMar 24, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-54920HigMar 16, 2026
    risk 0.51cvss 8.8epss 0.05

    This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to…

  • CVE-2026-25166HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.02

    Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

  • CVE-2025-11739HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

  • CVE-2026-27749HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.01

    Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET…

  • CVE-2025-60038HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially…

  • CVE-2025-60037HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially…

  • CVE-2025-60036HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious…

  • CVE-2025-60035HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious…

  • CVE-2025-33253HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and…

  • CVE-2025-33252HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

  • CVE-2025-33243HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-33241HigFeb 18, 2026
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2026-26208HigFeb 13, 2026
    risk 0.51cvss 7.8epss 0.01

    ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to…

  • CVE-2026-25925HigFeb 9, 2026
    risk 0.51cvss 7.8epss 0.00

    PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts the $type property in JSON files,…

  • CVE-2025-15351HigJan 23, 2026
    risk 0.51cvss 7.8epss 0.00

    Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is required to exploit this…

  • CVE-2025-15350HigJan 23, 2026
    risk 0.51cvss 7.8epss 0.00

    Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is required to exploit this…

  • CVE-2025-15348HigJan 23, 2026
    risk 0.51cvss 7.8epss 0.00

    Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu ShockLine. User interaction is required to exploit this…