CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,005 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 15 of 61
- CVE-2021-35196HIGHCVSS 7.8EG 7.82021-06-21
Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. NOTE: the vendor's p…
- CVE-2021-35215CRITICALCVSS 8.9EG 9.02021-09-01
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
- CVE-2021-35216CRITICALCVSS 8.9EG 9.02021-09-01
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can …
- CVE-2021-35217CRITICALCVSS 8.9EG 9.02021-09-08
Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecu…
- CVE-2021-35218CRITICALCVSS 8.9EG 9.02021-09-01
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the…
- CVE-2021-35227MEDIUMCVSS 4.7EG 4.72021-10-21
The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
- CVE-2021-35464CRITICALCVSS 9.8EG 9.8⚠ KEV2021-07-22
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single c…
- CVE-2021-35971CRITICALCVSS 9.8EG 9.82021-06-30
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.
- CVE-2021-36163CRITICALCVSS 9.8EG 9.82021-09-07
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuratio…
- CVE-2021-36231HIGHCVSS 8.8EG 8.82021-08-31
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.
- CVE-2021-36336CRITICALCVSS 9.8EG 9.82021-12-21
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
- CVE-2021-36483HIGHCVSS 8.8EG 8.82021-08-04
DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.
- CVE-2021-36564CRITICALCVSS 9.8EG 9.82021-12-06
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.
- CVE-2021-36567CRITICALCVSS 9.8EG 9.82021-12-06
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
- CVE-2021-36665HIGHCVSS 7.8EG 7.82022-07-12
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
- CVE-2021-36766HIGHCVSS 7.2EG 7.22021-07-30
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request…
- CVE-2021-36981HIGHCVSS 8.8EG 8.82021-08-31
In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.
- CVE-2021-37181CRITICALCVSS 10.0EG 10.02021-09-14
A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Comp…
- CVE-2021-37544CRITICALCVSS 9.8EG 9.82021-08-06
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
- CVE-2021-37578CRITICALCVSS 9.8EG 9.82021-07-29
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass param…
- CVE-2021-37579CRITICALCVSS 9.8EG 9.82021-09-09
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabl…
- CVE-2021-37632HIGHCVSS 8.1EG 8.12021-08-05
SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn642's Config Lib between 1.0.4 and 1.0.8 are affected by a vulnerability and can be exploited on both servers and client…
- CVE-2021-37678CRITICALCVSS 9.3EG 9.32021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](htt…
- CVE-2021-38241CRITICALCVSS 9.8EG 9.82022-12-16
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
- CVE-2021-3838CRITICALCVSS 9.8EG 9.82024-11-15
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the…
- CVE-2021-38585HIGHCVSS 7.2EG 7.22021-08-11
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
- CVE-2021-39132HIGHCVSS 8.8EG 8.82021-08-30
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an authorized user can upload a zip-format plugin with a crafted plugin.yaml, or a crafted aclpoli…
- CVE-2021-39139HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39140MEDIUMCVSS 6.5EG 6.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such …
- CVE-2021-39141HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39144CRITICALCVSS 8.5EG 9.0⚠ KEV2021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stre…
- CVE-2021-39145HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39146HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39147HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39148HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39149HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39150HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the pr…
- CVE-2021-39151HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39152HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the pr…
- CVE-2021-39153HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39154HIGHCVSS 8.5EG 8.52021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stre…
- CVE-2021-39207HIGHCVSS 8.4EG 8.42021-09-10
parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary …
- CVE-2021-39321HIGHCVSS 8.8EG 8.82021-10-21
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function…
- CVE-2021-39392CRITICALCVSS 9.8EG 9.82021-09-15
The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized A…
- CVE-2021-39676HIGHCVSS 7.8EG 7.82022-02-11
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. U…
- CVE-2021-40102CRITICALCVSS 9.1EG 9.12021-09-24
An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).
- CVE-2021-40719CRITICALCVSS 9.8EG 9.82021-10-21
Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialized on an Adobe Connect server. An attacker can leverage this…
- CVE-2021-40720CRITICALCVSS 9.8EG 9.82021-10-15
Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this…
- CVE-2021-40843HIGHCVSS 7.3EG 7.32021-10-13
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underl…
- CVE-2021-40865CRITICALCVSS 9.8EG 9.82021-10-25
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →