CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,005 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 13 of 61
- CVE-2021-21864HIGHCVSS 7.8EG 7.82021-08-02
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command …
- CVE-2021-21865HIGHCVSS 7.8EG 7.82021-08-02
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An at…
- CVE-2021-21866HIGHCVSS 7.8EG 7.82021-08-02
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command exe…
- CVE-2021-21867HIGHCVSS 7.8EG 7.82021-08-18
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command exe…
- CVE-2021-21868HIGHCVSS 7.8EG 7.82021-08-18
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execut…
- CVE-2021-21869HIGHCVSS 7.8EG 7.82021-08-25
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution…
- CVE-2021-21956HIGHCVSS 7.8EG 7.82022-04-14
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to tri…
- CVE-2021-22095MEDIUMCVSS 6.5EG 6.52021-11-30
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large me…
- CVE-2021-22097MEDIUMCVSS 6.5EG 6.52021-10-28
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct …
- CVE-2021-22439HIGHCVSS 8.1EG 8.12021-06-29
There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability. Successfully exploiting this vulnerability, the attacker can execute remote malicious cod…
- CVE-2021-22777HIGHCVSS 7.8EG 7.82021-07-21
A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.
- CVE-2021-22855CRITICALCVSS 9.8EG 9.82021-02-17
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
- CVE-2021-23338MEDIUMCVSS 6.6EG 6.62021-02-15
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
- CVE-2021-23420HIGHCVSS 7.7EG 7.72021-08-11
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
- CVE-2021-23592HIGHCVSS 7.7EG 7.72022-05-06
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
- CVE-2021-23758CRITICALCVSS 8.1EG 9.02021-12-03
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
- CVE-2021-23894CRITICALCVSS 9.6EG 9.62021-06-02
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully construct…
- CVE-2021-23895CRITICALCVSS 9.0EG 9.02021-06-02
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed…
- CVE-2021-24040CRITICALCVSS 9.8EG 9.82021-09-10
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v…
- CVE-2021-24066HIGHCVSS 8.8EG 8.82021-02-25
Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2021-24217HIGHCVSS 8.1EG 8.12021-04-12
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method i…
- CVE-2021-24280HIGHCVSS 8.8EG 8.82021-05-14
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.
- CVE-2021-24307HIGHCVSS 8.8EG 8.92021-05-24
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying ho…
- CVE-2021-24384CRITICALCVSS 9.8EG 9.82021-07-06
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issu…
- CVE-2021-24579HIGHCVSS 8.8EG 8.82021-08-30
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plu…
- CVE-2021-24857CRITICALCVSS 9.8EG 9.82021-12-13
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.
- CVE-2021-25151HIGHCVSS 8.8EG 8.82021-04-28
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25152HIGHCVSS 7.2EG 7.22021-04-28
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25274CRITICALCVSS 9.8EG 9.82021-02-03
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that t…
- CVE-2021-25294CRITICALCVSS 9.8EG 9.82021-01-18
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object in…
- CVE-2021-25641CRITICALCVSS 9.8EG 9.82021-06-01
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by ta…
- CVE-2021-25642HIGHCVSS 8.8EG 8.82022-08-25
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploi…
- CVE-2021-25738MEDIUMCVSS 6.7EG 6.72021-10-11
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
- CVE-2021-25758HIGHCVSS 7.8EG 7.82021-02-03
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
- CVE-2021-26295CRITICALCVSS 9.8EG 9.82021-03-22
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
- CVE-2021-26558HIGHCVSS 7.5EG 7.52021-11-11
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache Sh…
- CVE-2021-26857CRITICALCVSS 7.8EG 9.0⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-26912HIGHCVSS 8.1EG 8.32021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
- CVE-2021-26913HIGHCVSS 8.1EG 8.12021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
- CVE-2021-26914HIGHCVSS 8.1EG 8.92021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
- CVE-2021-26915HIGHCVSS 8.1EG 8.32021-02-08
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
- CVE-2021-27017MEDIUMCVSS 6.6EG 6.62025-02-07
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
- CVE-2021-27213CRITICALCVSS 9.8EG 9.82021-02-14
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.
- CVE-2021-27240HIGHCVSS 7.8EG 7.82021-03-29
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to expl…
- CVE-2021-27277HIGHCVSS 7.8EG 7.82021-04-22
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target sy…
- CVE-2021-27335CRITICALCVSS 9.8EG 9.82021-02-18
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.
- CVE-2021-27460CRITICALCVSS 10.0EG 10.02022-03-23
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a …
- CVE-2021-27462CRITICALCVSS 10.0EG 10.02022-03-23
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute…
- CVE-2021-27466CRITICALCVSS 10.0EG 10.02022-03-23
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to exe…
- CVE-2021-27470CRITICALCVSS 10.0EG 10.02022-03-23
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →