CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,006 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 22 of 61
- CVE-2023-25581CRITICALCVSS 9.2EG 9.22024-10-10
pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability affects systems that store externally controlled values in attributes of the `UserProfile` c…
- CVE-2023-25770CRITICALCVSS 9.8EG 9.82023-07-13
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-26153HIGHCVSS 8.3EG 8.32023-10-06
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** A…
- CVE-2023-26234CRITICALCVSS 6.6EG 9.82023-02-21
JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.
- CVE-2023-26326CRITICALCVSS 9.8EG 9.82023-02-23
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize …
- CVE-2023-26359CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-23
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Expl…
- CVE-2023-26436HIGHCVSS 7.1EG 7.12023-06-20
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary co…
- CVE-2023-26464HIGHCVSS 7.5EG 7.52023-03-10
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hash…
- CVE-2023-26512CRITICALCVSS 9.8EG 9.82023-07-17
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code exec…
- CVE-2023-26547HIGHCVSS 7.8EG 7.82023-03-27
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2023-26548HIGHCVSS 7.5EG 7.52023-03-27
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-26592LOWCVSS 3.8EG 3.82024-02-14
Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.
- CVE-2023-26779CRITICALCVSS 9.8EG 9.82023-03-03
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
- CVE-2023-27068CRITICALCVSS 9.8EG 9.82023-05-23
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
- CVE-2023-27296HIGHCVSS 8.8EG 8.82023-03-27
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apa…
- CVE-2023-27372CRITICALCVSS 9.8EG 9.82023-02-28
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
- CVE-2023-27459HIGHCVSS 7.4EG 7.42024-03-26
Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.
- CVE-2023-27531MEDIUMCVSS 5.3EG 5.32025-01-09
There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code
- CVE-2023-27978HIGHCVSS 7.8EG 7.82023-03-21
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a m…
- CVE-2023-28072HIGHCVSS 7.8EG 7.82023-09-04
Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious user could potentially send specially crafted requests to the .NET Remoting server to run arbitrary co…
- CVE-2023-28115CRITICALCVSS 9.8EG 9.82023-03-17
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `fi…
- CVE-2023-28310HIGHCVSS 8.0EG 8.02023-06-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-28323CRITICALCVSS 9.8EG 9.82023-07-01
A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities…
- CVE-2023-28462CRITICALCVSS 9.8EG 9.82023-03-30
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load maliciou…
- CVE-2023-28500CRITICALCVSS 9.8EG 9.82023-04-06
A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a spec…
- CVE-2023-28667CRITICALCVSS 9.8EG 9.82023-03-22
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being s…
- CVE-2023-28754HIGHCVSS 8.8EG 8.82023-07-19
Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the Shardi…
- CVE-2023-28782HIGHCVSS 8.3EG 8.32023-12-20
Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.
- CVE-2023-29006HIGHCVSS 8.8EG 8.82023-04-05
The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to…
- CVE-2023-29215CRITICALCVSS 9.8EG 9.82023-04-10
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote c…
- CVE-2023-29216CRITICALCVSS 9.8EG 9.82023-04-10
In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading t…
- CVE-2023-29234CRITICALCVSS 9.8EG 9.82023-12-15
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.
- CVE-2023-29300CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-12
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this i…
- CVE-2023-3001HIGHCVSS 7.8EG 7.82023-06-14
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a …
- CVE-2023-30262HIGHCVSS 8.8EG 8.82023-06-09
An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service.
- CVE-2023-30534MEDIUMCVSS 4.3EG 4.32023-09-05
Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the n…
- CVE-2023-30898CRITICALCVSS 9.9EG 9.92023-05-09
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Vi…
- CVE-2023-30899CRITICALCVSS 9.9EG 9.92023-05-09
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Vi…
- CVE-2023-31058HIGHCVSS 7.5EG 7.52023-05-22
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users…
- CVE-2023-31222CRITICALCVSS 9.8EG 9.82023-06-29
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima syste…
- CVE-2023-3154HIGHCVSS 7.5EG 7.52023-10-16
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
- CVE-2023-31890CRITICALCVSS 9.8EG 9.82023-05-16
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.
- CVE-2023-32031CRITICALCVSS 8.8EG 9.02023-06-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-32242CRITICALCVSS 9.8EG 9.82023-12-21
Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.
- CVE-2023-3232MEDIUMCVSS 6.3EG 6.32023-06-14
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The…
- CVE-2023-32336HIGHCVSS 8.8EG 8.82023-05-22
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.
- CVE-2023-3234MEDIUMCVSS 4.3EG 4.32023-06-14
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/v1/PublicController.php. The manipulation leads to deserial…
- CVE-2023-32513HIGHCVSS 7.5EG 7.52023-12-28
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.
- CVE-2023-3259CRITICALCVSS 9.8EG 9.82023-08-14
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to …
- CVE-2023-32636MEDIUMCVSS 4.7EG 4.72023-09-14
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does n…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →