CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,005 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 16 of 61
- CVE-2021-4104HIGHCVSS 7.5EG 8.92021-12-14
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causi…
- CVE-2021-41078HIGHCVSS 7.8EG 7.82021-10-26
Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.
- CVE-2021-41110CRITICALCVSS 9.1EG 9.12021-10-01
cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-3…
- CVE-2021-41129HIGHCVSS 8.1EG 8.12021-10-06
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value no…
- CVE-2021-4118HIGHCVSS 7.8EG 7.82021-12-23
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
- CVE-2021-4125HIGHCVSS 8.1EG 8.12022-08-24
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive c…
- CVE-2021-41419CRITICALCVSS 9.8EG 9.82022-07-18
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
- CVE-2021-41588HIGHCVSS 8.1EG 8.12021-09-24
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.
- CVE-2021-41616CRITICALCVSS 9.8EG 9.82021-09-30
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjects…
- CVE-2021-41766HIGHCVSS 8.1EG 8.12022-01-26
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the defau…
- CVE-2021-4178MEDIUMCVSS 6.7EG 6.72022-08-24
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
- CVE-2021-42090CRITICALCVSS 9.8EG 9.82021-10-07
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
- CVE-2021-42125CRITICALCVSS 8.8EG 9.02021-12-07
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
- CVE-2021-42127CRITICALCVSS 9.8EG 9.82021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
- CVE-2021-42130HIGHCVSS 8.8EG 8.92021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
- CVE-2021-42237CRITICALCVSS 9.8EG 9.8⚠ KEV2021-11-05
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required…
- CVE-2021-42392CRITICALCVSS 9.8EG 9.82022-01-10
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote …
- CVE-2021-42550MEDIUMCVSS 6.6EG 6.62021-12-16
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
- CVE-2021-42631HIGHCVSS 8.1EG 8.12022-01-31
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
- CVE-2021-42698HIGHCVSS 7.8EG 7.82021-11-05
Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corru…
- CVE-2021-43297CRITICALCVSS 9.8EG 9.82022-01-10
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessia…
- CVE-2021-43360HIGHCVSS 8.8EG 8.82021-12-01
Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and co…
- CVE-2021-43853HIGHCVSS 8.7EG 8.72021-12-22
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious us…
- CVE-2021-44029CRITICALCVSS 9.8EG 9.82021-12-22
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage…
- CVE-2021-44228CRITICALCVSS 10.0EG 10.0⚠ KEV2021-12-10
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoin…
- CVE-2021-4451MEDIUMCVSS 6.6EG 6.62024-10-16
The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization ca…
- CVE-2021-44677CRITICALCVSS 9.8EG 9.82021-12-06
An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44678CRITICALCVSS 9.8EG 9.82021-12-06
An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44679CRITICALCVSS 9.8EG 9.82021-12-06
An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44680CRITICALCVSS 9.8EG 9.82021-12-06
An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44681CRITICALCVSS 9.8EG 9.82021-12-06
An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-44682CRITICALCVSS 9.8EG 9.82021-12-06
An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications…
- CVE-2021-45394HIGHCVSS 8.8EG 8.82022-01-18
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document.
- CVE-2021-45899CRITICALCVSS 9.8EG 9.82022-01-28
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
- CVE-2021-46364HIGHCVSS 7.8EG 7.82022-02-11
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.
- CVE-2021-47952CRITICALCVSS 9.8EG 9.82026-05-16
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py…
- CVE-2022-0138HIGHCVSS 7.5EG 7.52022-02-18
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary cl…
- CVE-2022-0538HIGHCVSS 7.5EG 7.52022-02-09
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
- CVE-2022-0573HIGHCVSS 8.8EG 8.82022-05-16
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged aut…
- CVE-2022-0749CRITICALCVSS 7.4EG 9.82022-03-17
This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appro…
- CVE-2022-1032HIGHCVSS 7.2EG 7.22022-03-29
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
- CVE-2022-1118HIGHCVSS 8.6EG 8.62022-05-17
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This all…
- CVE-2022-1415HIGHCVSS 8.1EG 8.12023-09-11
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve cod…
- CVE-2022-1463HIGHCVSS 8.8EG 8.82022-05-10
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PH…
- CVE-2022-1471CRITICALCVSS 8.3EG 9.02022-12-01
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor…
- CVE-2022-1660CRITICALCVSS 9.8EG 9.82022-06-02
The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.
- CVE-2022-1984HIGHCVSS 4.5EG 7.82022-07-19
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized pay…
- CVE-2022-20195MEDIUMCVSS 5.0EG 5.02022-06-15
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitati…
- CVE-2022-20763HIGHCVSS 5.4EG 8.82022-04-06
A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code. This vulnerability is due to improper deserialization of Java code within login requ…
- CVE-2022-21341MEDIUMCVSS 5.3EG 5.32022-01-19
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise …
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →