VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 98 of 167
  • CVE-2024-14021HigJan 12, 2026
    risk 0.51cvss 7.8epss 0.00

    LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py. The function uses pickle.load() to deserialize multi_embed_store.pkl from a…

  • CVE-2026-22187HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.01

    Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without…

  • CVE-2025-15276HigDec 31, 2025
    risk 0.51cvss 7.8epss 0.00

    FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-14930HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14929HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required…

  • CVE-2025-14925HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in…

  • CVE-2025-14924HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2025-14922HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this…

  • CVE-2025-14921HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to…

  • CVE-2025-14920HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2025-33226HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-41700HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

  • CVE-2025-11622HigOct 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-41701HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context.

  • CVE-2025-48535HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution…

  • CVE-2025-32312HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next process due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2025-9365HigSep 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.

  • CVE-2025-7976HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu ShockLine. User interaction is required to exploit this…

  • CVE-2025-9188HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.01

    There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions…

  • CVE-2025-23303HigAug 13, 2025
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.