CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,006 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 19 of 61
- CVE-2022-36006HIGHCVSS 7.9EG 7.92022-08-15
Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute…
- CVE-2022-36038HIGHCVSS 8.8EG 8.82022-09-06
CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially craft…
- CVE-2022-36119HIGHCVSS 8.8EG 8.82022-08-25
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Se…
- CVE-2022-3679HIGHCVSS 8.8EG 8.82023-01-09
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable ga…
- CVE-2022-36944CRITICALCVSS 9.8EG 9.82022-09-23
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows atta…
- CVE-2022-36957HIGHCVSS 7.2EG 7.22022-10-20
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-36958CRITICALCVSS 8.8EG 9.02022-10-20
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-36964HIGHCVSS 8.8EG 8.82022-11-29
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-36971HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2022-36974CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2022-36977CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2022-36978CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2022-37021CRITICALCVSS 9.8EG 9.82022-08-31
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JM…
- CVE-2022-37022HIGHCVSS 8.8EG 8.82022-08-31
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to…
- CVE-2022-37023MEDIUMCVSS 6.5EG 6.52022-08-31
Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Ap…
- CVE-2022-37378HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or o…
- CVE-2022-37936CRITICALCVSS 9.8EG 9.82023-03-01
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
- CVE-2022-38108HIGHCVSS 7.2EG 8.52022-10-20
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-38111CRITICALCVSS 7.2EG 9.02023-02-15
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-38142CRITICALCVSS 9.8EG 9.82022-10-31
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to…
- CVE-2022-38352CRITICALCVSS 9.8EG 9.82022-09-15
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- CVE-2022-3861HIGHCVSS 8.8EG 8.82022-11-21
The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed …
- CVE-2022-38650CRITICALCVSS 10.0EG 10.02022-11-12
A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operati…
- CVE-2022-38652CRITICALCVSS 9.9EG 9.92022-11-12
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host …
- CVE-2022-3900CRITICALCVSS 9.8EG 9.82022-12-12
The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection v…
- CVE-2022-39008CRITICALCVSS 9.1EG 9.12022-09-16
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.
- CVE-2022-39198CRITICALCVSS 9.8EG 9.82022-10-18
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x versio…
- CVE-2022-39256CRITICALCVSS 9.0EG 9.02022-09-27
Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploi…
- CVE-2022-39297HIGHCVSS 7.7EG 7.72022-10-12
MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-cms`, and ultima…
- CVE-2022-39298HIGHCVSS 7.7EG 7.72022-10-12
MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization and SEO, etc. Attackers can deserialize arbitrary data on affected versions of `melisplatfor…
- CVE-2022-39311CRITICALCVSS 9.1EG 9.12022-10-14
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a m…
- CVE-2022-39312CRITICALCVSS 9.8EG 9.82022-10-25
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the …
- CVE-2022-39379MEDIUMCVSS 3.1EG 4.72022-11-02
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers t…
- CVE-2022-39944HIGHCVSS 8.8EG 8.82022-10-26
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data sou…
- CVE-2022-40238HIGHCVSS 8.8EG 8.82022-10-26
A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's …
- CVE-2022-40314CRITICALCVSS 9.8EG 9.82022-09-30
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
- CVE-2022-4043HIGHCVSS 7.2EG 7.22023-01-09
The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2022-40609HIGHCVSS 8.1EG 8.12023-08-02
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulner…
- CVE-2022-40889CRITICALCVSS 9.8EG 9.82022-10-18
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
- CVE-2022-40955HIGHCVSS 8.8EG 8.82022-09-20
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLon…
- CVE-2022-41082CRITICALCVSS 8.0EG 9.0⚠ KEV2022-10-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-41137HIGHCVSS 8.3EG 8.32024-12-05
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization …
- CVE-2022-4120CRITICALCVSS 9.8EG 9.82022-12-26
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object inje…
- CVE-2022-41203HIGHCVSS 8.8EG 8.82022-11-08
In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious seri…
- CVE-2022-41237CRITICALCVSS 9.8EG 9.82022-09-21
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
- CVE-2022-41596HIGHCVSS 7.5EG 7.52022-12-20
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.
- CVE-2022-41778CRITICALCVSS 9.8EG 9.82023-01-13
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized object…
- CVE-2022-41779CRITICALCVSS 8.8EG 9.82022-10-31
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets …
- CVE-2022-41875CRITICALCVSS 10.0EG 10.02022-11-23
A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked s…
- CVE-2022-41922HIGHCVSS 8.1EG 8.12022-11-23
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →