CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,006 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 20 of 61
- CVE-2022-41958HIGHCVSS 7.3EG 7.32022-11-25
super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. Th…
- CVE-2022-41966HIGHCVSS 8.2EG 8.22022-12-28
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed inpu…
- CVE-2022-42003HIGHCVSS 7.5EG 7.52022-10-02
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feat…
- CVE-2022-42004HIGHCVSS 7.5EG 7.52022-10-02
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain custom…
- CVE-2022-4237HIGHCVSS 8.8EG 8.82023-01-02
The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscr…
- CVE-2022-42919HIGHCVSS 7.8EG 7.82022-11-07
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be de…
- CVE-2022-43019CRITICALCVSS 9.8EG 9.82022-10-19
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
- CVE-2022-4302HIGHCVSS 7.2EG 7.22023-01-02
The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2022-4323HIGHCVSS 7.2EG 7.22023-01-23
The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
- CVE-2022-4324HIGHCVSS 7.2EG 7.22023-01-02
The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling …
- CVE-2022-43567HIGHCVSS 8.8EG 8.82022-11-04
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gatewa…
- CVE-2022-44351CRITICALCVSS 9.8EG 9.82022-12-07
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
- CVE-2022-44371CRITICALCVSS 9.8EG 9.82022-12-07
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
- CVE-2022-44542CRITICALCVSS 9.8EG 9.82022-11-01
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.
- CVE-2022-44558CRITICALCVSS 9.8EG 9.82022-11-09
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44559CRITICALCVSS 9.8EG 9.82022-11-09
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44562CRITICALCVSS 9.8EG 9.82022-11-09
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44645HIGHCVSS 8.8EG 8.82023-01-31
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL dat…
- CVE-2022-4489HIGHCVSS 7.2EG 7.22023-02-06
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2022-45047CRITICALCVSS 9.8EG 9.82022-11-16
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor u…
- CVE-2022-45077HIGHCVSS 6.3EG 8.82022-11-17
Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
- CVE-2022-45083MEDIUMCVSS 6.6EG 6.62024-01-19
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plug…
- CVE-2022-45134CRITICALCVSS 9.8EG 9.82025-08-22
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code execution when being processed.
- CVE-2022-45136CRITICALCVSS 9.8EG 9.82022-11-14
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is…
- CVE-2022-45147HIGHCVSS 7.8EG 7.82024-07-09
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Affected applications do not properly restr…
- CVE-2022-45185HIGHCVSS 8.8EG 8.82025-01-07
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
- CVE-2022-45378CRITICALCVSS 9.8EG 9.82022-11-14
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are avail…
- CVE-2022-45845MEDIUMCVSS 4.3EG 4.32024-01-19
Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.
- CVE-2022-45923HIGHCVSS 8.8EG 8.82023-01-18
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a …
- CVE-2022-45982CRITICALCVSS 9.8EG 9.82023-02-08
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- CVE-2022-46366CRITICALCVSS 9.8EG 9.82022-12-02
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability …
- CVE-2022-46478CRITICALCVSS 9.8EG 9.82023-01-13
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
- CVE-2022-4680HIGHCVSS 7.2EG 7.22023-01-30
The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2022-47083HIGHCVSS 8.8EG 8.82023-01-10
A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.
- CVE-2022-47503HIGHCVSS 7.2EG 7.22023-02-15
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-47504HIGHCVSS 7.2EG 7.22023-02-15
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-47507HIGHCVSS 7.2EG 7.22023-02-15
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2022-47599MEDIUMCVSS 5.5EG 5.52023-12-20
Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File…
- CVE-2022-47986CRITICALCVSS 9.8EG 9.8⚠ KEV2023-02-17
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit thi…
- CVE-2022-4815HIGHCVSS 8.0EG 8.02023-05-24
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
- CVE-2022-48282MEDIUMCVSS 6.6EG 6.62023-02-21
Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. …
- CVE-2022-4890CRITICALCVSS 6.3EG 9.82023-01-16
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The man…
- CVE-2023-0232CRITICALCVSS 9.8EG 9.82023-02-21
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
- CVE-2023-0669CRITICALCVSS 7.2EG 9.0⚠ KEV2023-02-06
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version…
- CVE-2023-0925CRITICALCVSS 9.8EG 9.82023-09-06
Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high po…
- CVE-2023-0960MEDIUMCVSS 4.7EG 4.72023-02-22
A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. T…
- CVE-2023-1133CRITICALCVSS 9.8EG 9.82023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the conten…
- CVE-2023-1139HIGHCVSS 8.8EG 8.82023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in re…
- CVE-2023-1145HIGHCVSS 7.8EG 7.82023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resu…
- CVE-2023-1196HIGHCVSS 8.8EG 8.82023-05-02
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a …
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →