CWE-502— Deserialization of Untrusted Data
2,468 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 12 of 50
- CVE-2021-25152HIGHCVSS 7.2EG 7.22021-04-28
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25274CRITICALCVSS 9.8EG 9.82021-02-03
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that t…
- CVE-2021-25294CRITICALCVSS 9.8EG 9.82021-01-18
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object in…
- CVE-2021-25641CRITICALCVSS 9.8EG 9.82021-06-01
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by ta…
- CVE-2021-25642HIGHCVSS 8.8EG 8.82022-08-25
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploi…
- CVE-2021-25738MEDIUMCVSS 6.7EG 6.72021-10-11
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
- CVE-2021-25758HIGHCVSS 7.8EG 7.82021-02-03
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
- CVE-2021-26295CRITICALCVSS 9.8EG 9.82021-03-22
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
- CVE-2021-26558HIGHCVSS 7.5EG 7.52021-11-11
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache Sh…
- CVE-2021-26857HIGHCVSS 7.8EG 9.0⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-26912HIGHCVSS 8.1EG 8.12021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
- CVE-2021-26913HIGHCVSS 8.1EG 8.12021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
- CVE-2021-26914HIGHCVSS 8.1EG 8.12021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
- CVE-2021-26915HIGHCVSS 8.1EG 8.12021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
- CVE-2021-27017MEDIUMCVSS 6.6EG 6.62025-02-07
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
- CVE-2021-27213CRITICALCVSS 9.8EG 9.82021-02-14
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.
- CVE-2021-27240HIGHCVSS 7.8EG 7.82021-03-29
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to expl…
- CVE-2021-27277HIGHCVSS 7.8EG 7.82021-04-22
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target sy…
- CVE-2021-27335CRITICALCVSS 9.8EG 9.82021-02-18
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.
- CVE-2021-27460CRITICALCVSS 10.0EG 9.82022-03-23
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a …
- CVE-2021-27462CRITICALCVSS 10.0EG 9.82022-03-23
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute…
- CVE-2021-27466CRITICALCVSS 10.0EG 9.82022-03-23
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to exe…
- CVE-2021-27470CRITICALCVSS 10.0EG 9.82022-03-23
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute…
- CVE-2021-27475HIGHCVSS 8.6EG 8.62022-03-23
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Conne…
- CVE-2021-27850CRITICALCVSS 9.8EG 9.82021-04-15
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-201…
- CVE-2021-27852CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-27
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
- CVE-2021-28254CRITICALCVSS 9.8EG 9.82023-04-19
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
- CVE-2021-29150HIGHCVSS 7.2EG 7.22021-07-08
A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
- CVE-2021-29200CRITICALCVSS 9.8EG 9.82021-04-27
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
- CVE-2021-29476CRITICALCVSS 9.8EG 9.82021-04-27
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
- CVE-2021-29485CRITICALCVSS 9.9EG 9.92021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a maliciously crafted Java deserialization gadget chain leveraged against the Ratpack session …
- CVE-2021-29505HIGHCVSS 7.5EG 9.02021-05-28
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processe…
- CVE-2021-29508CRITICALCVSS 9.1EG 9.12021-05-11
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving e…
- CVE-2021-29654HIGHCVSS 7.2EG 7.22021-04-14
AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.
- CVE-2021-29781CRITICALCVSS 9.8EG 9.82021-07-30
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute …
- CVE-2021-3007CRITICALCVSS 9.8EG 9.82021-01-04
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Str…
- CVE-2021-30128CRITICALCVSS 9.8EG 9.82021-04-27
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
- CVE-2021-30179CRITICALCVSS 9.8EG 9.82021-06-01
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first a…
- CVE-2021-3035MEDIUMCVSS 6.7EG 6.72021-04-20
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 vers…
- CVE-2021-3040MEDIUMCVSS 6.7EG 6.72021-06-10
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 ver…
- CVE-2021-31010HIGHCVSS 7.5EG 9.0⚠ KEV2021-08-24
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circum…
- CVE-2021-31474CRITICALCVSS 9.8EG 9.82021-05-21
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists withi…
- CVE-2021-3160CRITICALCVSS 9.8EG 9.82021-01-28
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in…
- CVE-2021-31649CRITICALCVSS 9.8EG 9.82021-06-24
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- CVE-2021-31680HIGHCVSS 7.8EG 7.82023-07-31
Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.
- CVE-2021-31681HIGHCVSS 7.8EG 7.82023-07-31
Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.
- CVE-2021-31819CRITICALCVSS 9.8EG 9.82021-09-22
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
- CVE-2021-32075CRITICALCVSS 9.8EG 9.82021-05-24
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
- CVE-2021-32098CRITICALCVSS 9.8EG 9.82021-05-07
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
- CVE-2021-32568HIGHCVSS 7.8EG 7.82021-09-06
mrdoc is vulnerable to Deserialization of Untrusted Data
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →