CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,006 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 18 of 61
- CVE-2022-2903HIGHCVSS 7.2EG 7.22022-09-26
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget c…
- CVE-2022-29063CRITICALCVSS 9.8EG 9.82022-09-02
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, a…
- CVE-2022-29363CRITICALCVSS 9.8EG 9.82022-05-12
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
- CVE-2022-29528CRITICALCVSS 9.8EG 9.82022-04-20
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
- CVE-2022-29615LOWCVSS 3.4EG 3.42022-06-14
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associ…
- CVE-2022-29805CRITICALCVSS 9.8EG 9.82022-08-19
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
- CVE-2022-29875CRITICALCVSS 9.8EG 9.82022-06-01
A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha …
- CVE-2022-29936HIGHCVSS 8.8EG 8.82022-04-29
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation product.
- CVE-2022-30287HIGHCVSS 8.0EG 8.72022-07-28
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
- CVE-2022-30981HIGHCVSS 8.8EG 8.82022-07-17
An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.
- CVE-2022-31115HIGHCVSS 8.8EG 8.82022-06-30
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe de…
- CVE-2022-31199CRITICALCVSS 9.8EG 9.8⚠ KEV2022-11-08
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist…
- CVE-2022-31604CRITICALCVSS 9.8EG 9.82022-07-01
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged n…
- CVE-2022-31605CRITICALCVSS 9.8EG 9.82022-07-01
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to c…
- CVE-2022-31680CRITICALCVSS 9.1EG 9.12022-10-07
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operati…
- CVE-2022-31710HIGHCVSS 7.5EG 7.52023-01-26
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
- CVE-2022-32224CRITICALCVSS 9.8EG 9.82022-12-05
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL in…
- CVE-2022-32521CRITICALCVSS 7.1EG 9.82023-01-30
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server. Affected Products: Data Center Expert (Versions prio…
- CVE-2022-32601HIGHCVSS 7.8EG 7.82022-11-08
In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID…
- CVE-2022-3291MEDIUMCVSS 6.5EG 6.52022-10-17
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache
- CVE-2022-33107CRITICALCVSS 9.8EG 9.82022-06-29
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted …
- CVE-2022-33315HIGHCVSS 7.8EG 7.82022-07-20
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97…
- CVE-2022-33316HIGHCVSS 7.8EG 7.82022-07-20
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97…
- CVE-2022-33318CRITICALCVSS 9.8EG 9.82022-07-20
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97…
- CVE-2022-33320HIGHCVSS 7.8EG 7.82022-07-20
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97…
- CVE-2022-3334HIGHCVSS 7.2EG 7.22022-10-31
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present…
- CVE-2022-3335HIGHCVSS 7.2EG 7.22022-10-25
The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable…
- CVE-2022-3342HIGHCVSS 7.5EG 7.52023-10-20
The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a non…
- CVE-2022-3357HIGHCVSS 8.8EG 8.82022-10-31
The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is pr…
- CVE-2022-3359HIGHCVSS 8.8EG 8.82022-12-12
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suita…
- CVE-2022-3360HIGHCVSS 8.1EG 8.12022-10-31
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution …
- CVE-2022-3366HIGHCVSS 7.2EG 7.22022-10-31
The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on mul…
- CVE-2022-3374HIGHCVSS 7.2EG 7.22022-10-31
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a…
- CVE-2022-3380HIGHCVSS 7.2EG 7.22022-10-31
The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget ch…
- CVE-2022-33900HIGHCVSS 4.1EG 7.22022-08-22
PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
- CVE-2022-33947MEDIUMCVSS 5.4EG 6.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authen…
- CVE-2022-3417HIGHCVSS 8.8EG 8.82023-01-09
The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget c…
- CVE-2022-3425HIGHCVSS 7.2EG 7.22023-01-23
The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2022-34268CRITICALCVSS 9.8EG 9.82023-12-25
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
- CVE-2022-34668CRITICALCVSS 9.8EG 9.82022-08-29
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confiden…
- CVE-2022-3490HIGHCVSS 7.2EG 7.22022-11-28
The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suita…
- CVE-2022-35223CRITICALCVSS 9.8EG 9.82022-08-02
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthent…
- CVE-2022-3525HIGHCVSS 8.8EG 8.82022-11-20
Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.
- CVE-2022-3536HIGHCVSS 8.8EG 8.82022-11-07
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PH…
- CVE-2022-35405CRITICALCVSS 9.8EG 9.8⚠ KEV2022-07-19
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
- CVE-2022-35411CRITICALCVSS 9.8EG 9.82022-07-08
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the …
- CVE-2022-3568HIGHCVSS 8.8EG 8.82023-02-10
The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to call files using a PHA…
- CVE-2022-35857CRITICALCVSS 9.8EG 9.82022-07-13
kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.
- CVE-2022-35870HIGHCVSS 7.8EG 8.12022-07-25
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentic…
- CVE-2022-35872HIGHCVSS 7.8EG 7.82022-07-25
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit …
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →