CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,005 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 14 of 61
- CVE-2021-27475HIGHCVSS 8.6EG 8.62022-03-23
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Conne…
- CVE-2021-27850CRITICALCVSS 9.8EG 9.82021-04-15
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-201…
- CVE-2021-27852CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-27
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
- CVE-2021-28254CRITICALCVSS 9.8EG 9.82023-04-19
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
- CVE-2021-29150HIGHCVSS 7.2EG 7.22021-07-08
A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
- CVE-2021-29200CRITICALCVSS 9.8EG 9.82021-04-27
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
- CVE-2021-29476CRITICALCVSS 9.8EG 9.82021-04-27
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
- CVE-2021-29485CRITICALCVSS 9.9EG 9.92021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a maliciously crafted Java deserialization gadget chain leveraged against the Ratpack session …
- CVE-2021-29505HIGHCVSS 7.5EG 8.82021-05-28
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processe…
- CVE-2021-29508CRITICALCVSS 9.1EG 9.12021-05-11
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving e…
- CVE-2021-29654HIGHCVSS 7.2EG 7.22021-04-14
AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.
- CVE-2021-29781CRITICALCVSS 9.8EG 9.82021-07-30
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute …
- CVE-2021-3007CRITICALCVSS 9.8EG 9.82021-01-04
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Str…
- CVE-2021-30128CRITICALCVSS 9.8EG 9.82021-04-27
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
- CVE-2021-30179CRITICALCVSS 9.8EG 9.82021-06-01
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first a…
- CVE-2021-3035MEDIUMCVSS 6.7EG 6.72021-04-20
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 vers…
- CVE-2021-3040MEDIUMCVSS 6.7EG 6.72021-06-10
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 ver…
- CVE-2021-31010CRITICALCVSS 7.5EG 9.0⚠ KEV2021-08-24
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circum…
- CVE-2021-31474CRITICALCVSS 9.8EG 9.82021-05-21
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists withi…
- CVE-2021-3160CRITICALCVSS 9.8EG 9.82021-01-28
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in…
- CVE-2021-31649CRITICALCVSS 9.8EG 9.82021-06-24
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- CVE-2021-31680HIGHCVSS 7.8EG 7.82023-07-31
Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.
- CVE-2021-31681HIGHCVSS 7.8EG 7.82023-07-31
Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.
- CVE-2021-31819CRITICALCVSS 9.8EG 9.82021-09-22
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
- CVE-2021-32075CRITICALCVSS 9.8EG 9.82021-05-24
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
- CVE-2021-32098CRITICALCVSS 9.8EG 9.82021-05-07
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
- CVE-2021-32568HIGHCVSS 7.8EG 7.82021-09-06
mrdoc is vulnerable to Deserialization of Untrusted Data
- CVE-2021-32634HIGHCVSS 7.2EG 7.22021-05-21
Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the [`WorkSpaceClientEnqueue.action`](https://github.com/NationalSecurityAgen…
- CVE-2021-32742HIGHCVSS 7.5EG 7.52021-07-09
Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing server memory and/or crashing the server (Denial of Service) for applications where untru…
- CVE-2021-32824CRITICALCVSS 9.8EG 9.82023-01-03
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to…
- CVE-2021-32828MEDIUMCVSS 5.4EG 5.42023-01-05
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code…
- CVE-2021-32836HIGHCVSS 7.5EG 8.12021-09-09
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able…
- CVE-2021-3287CRITICALCVSS 9.8EG 9.82021-04-22
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
- CVE-2021-32935CRITICALCVSS 8.8EG 9.82022-05-23
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.
- CVE-2021-33026CRITICALCVSS 9.8EG 9.82021-05-13
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redi…
- CVE-2021-33175HIGHCVSS 7.5EG 7.52021-06-08
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs cause the message broker to consume large amounts of memory…
- CVE-2021-33176HIGHCVSS 7.5EG 7.52021-06-08
VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs cause the message broker to consume large amounts o…
- CVE-2021-33207CRITICALCVSS 9.8EG 9.82022-04-05
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
- CVE-2021-33420CRITICALCVSS 9.8EG 9.82022-12-15
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
- CVE-2021-33728HIGHCVSS 7.2EG 7.22021-10-12
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content by the a…
- CVE-2021-33790CRITICALCVSS 9.8EG 9.82021-05-31
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the…
- CVE-2021-33806CRITICALCVSS 9.8EG 9.82021-06-03
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.
- CVE-2021-33898HIGHCVSS 8.1EG 8.12021-06-06
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code ex…
- CVE-2021-34066CRITICALCVSS 9.8EG 9.82021-08-30
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.
- CVE-2021-34371CRITICALCVSS 9.8EG 9.82021-08-05
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies w…
- CVE-2021-34393MEDIUMCVSS 4.2EG 4.22021-06-22
Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causi…
- CVE-2021-34394MEDIUMCVSS 4.2EG 4.22021-06-22
Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may l…
- CVE-2021-34520HIGHCVSS 8.1EG 8.12021-07-14
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2021-34992HIGHCVSS 8.8EG 8.82021-11-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required to exploit this vulnerability. The specific flaw exists within Composite.dll. The issue res…
- CVE-2021-35095HIGHCVSS 8.4EG 8.42022-06-14
Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →