CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,006 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 21 of 61
- CVE-2023-1347HIGHCVSS 7.2EG 7.22023-05-08
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
- CVE-2023-1381HIGHCVSS 8.8EG 8.82023-04-10
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be…
- CVE-2023-1399CRITICALCVSS 7.8EG 9.82023-03-27
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.
- CVE-2023-1405HIGHCVSS 7.5EG 7.52024-01-16
The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
- CVE-2023-1549HIGHCVSS 7.2EG 7.22023-05-15
The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
- CVE-2023-1552HIGHCVSS 6.4EG 7.82023-04-11
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's conte…
- CVE-2023-1650CRITICALCVSS 9.8EG 9.82023-05-08
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
- CVE-2023-1669HIGHCVSS 7.2EG 7.22023-05-02
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2023-1714HIGHCVSS 8.8EG 8.82023-11-01
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR d…
- CVE-2023-1967CRITICALCVSS 9.8EG 9.82023-04-27
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.
- CVE-2023-20102HIGHCVSS 8.8EG 8.82023-04-05
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient s…
- CVE-2023-2042HIGHCVSS 6.3EG 8.82023-04-14
A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Server Handler. The manipulation leads to deserialization. The a…
- CVE-2023-20852CRITICALCVSS 9.8EG 9.82023-04-27
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary syst…
- CVE-2023-20853CRITICALCVSS 9.8EG 9.82023-04-27
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perf…
- CVE-2023-20864CRITICALCVSS 9.8EG 9.82023-04-20
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
- CVE-2023-20878HIGHCVSS 7.2EG 7.22023-05-12
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
- CVE-2023-20888CRITICALCVSS 8.8EG 9.02023-06-07
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserializatio…
- CVE-2023-20944HIGHCVSS 7.8EG 7.82023-02-28
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…
- CVE-2023-21124HIGHCVSS 7.8EG 7.82023-06-15
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2023-21205MEDIUMCVSS 5.5EG 5.52023-06-28
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n…
- CVE-2023-21206MEDIUMCVSS 4.4EG 4.42023-06-28
In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with System execution privileges needed. User interaction is not n…
- CVE-2023-21209MEDIUMCVSS 6.7EG 6.72023-06-28
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl…
- CVE-2023-2141HIGHCVSS 8.5EG 8.52023-04-21
An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.
- CVE-2023-21529CRITICALCVSS 8.8EG 9.0⚠ KEV2023-02-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-21538HIGHCVSS 7.5EG 7.52023-01-10
.NET Denial of Service Vulnerability
- CVE-2023-21568HIGHCVSS 7.3EG 7.32023-02-14
Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability
- CVE-2023-21703MEDIUMCVSS 6.5EG 6.52023-02-14
Azure Data Box Gateway Remote Code Execution Vulnerability
- CVE-2023-21706HIGHCVSS 8.8EG 8.82023-02-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-21707CRITICALCVSS 8.8EG 9.02023-02-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-21710HIGHCVSS 7.2EG 7.22023-02-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-21713HIGHCVSS 8.8EG 8.82023-02-14
Microsoft SQL Server Remote Code Execution Vulnerability
- CVE-2023-21744HIGHCVSS 8.8EG 8.82023-01-10
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-21745HIGHCVSS 8.0EG 8.02023-01-10
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-21762HIGHCVSS 8.0EG 8.02023-01-10
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-21779HIGHCVSS 7.8EG 7.82023-01-10
Visual Studio Code Remote Code Execution Vulnerability
- CVE-2023-21839CRITICALCVSS 7.5EG 9.0⚠ KEV2023-01-18
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2023-22850HIGHCVSS 8.8EG 8.82023-01-14
Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.
- CVE-2023-2288HIGHCVSS 8.8EG 8.82023-05-30
The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.
- CVE-2023-23638MEDIUMCVSS 5.0EG 5.02023-03-08
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior version…
- CVE-2023-23649HIGHCVSS 8.1EG 8.12024-03-28
Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a through 2.1.
- CVE-2023-23836HIGHCVSS 7.2EG 8.82023-02-15
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrar…
- CVE-2023-23930MEDIUMCVSS 5.5EG 5.52023-10-11
vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default serialization module but that has known security issues. All users of vantage6 that post tas…
- CVE-2023-24162CRITICALCVSS 9.8EG 9.82023-01-31
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
- CVE-2023-24621HIGHCVSS 7.8EG 7.82023-08-25
An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.
- CVE-2023-24971HIGHCVSS 7.5EG 7.52023-07-31
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.
- CVE-2023-24997CRITICALCVSS 9.8EG 9.82023-02-01
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https:/…
- CVE-2023-2500HIGHCVSS 8.8EG 8.82023-05-25
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' paramete…
- CVE-2023-25135CRITICALCVSS 9.8EG 9.82023-02-03
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling uns…
- CVE-2023-25194CRITICALCVSS 8.8EG 9.02023-02-07
A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL…
- CVE-2023-25558HIGHCVSS 7.5EG 7.52023-02-11
DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The processing of the `id_token` is done in an unsafe manner which is not properly accounted …
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →