CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,006 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 23 of 61
- CVE-2023-32665MEDIUMCVSS 5.5EG 5.52023-09-14
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.
- CVE-2023-32735MEDIUMCVSS 6.5EG 6.52024-07-09
A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 7), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2), SIMATIC STEP 7 V16 (All versi…
- CVE-2023-32736HIGHCVSS 7.3EG 7.32024-11-12
A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18…
- CVE-2023-32737MEDIUMCVSS 6.3EG 6.32024-07-09
A vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-controllable input. This could allow an attacke…
- CVE-2023-32795HIGHCVSS 8.2EG 8.22023-12-28
Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.
- CVE-2023-33008MEDIUMCVSS 5.3EG 5.32023-07-07
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize in…
- CVE-2023-3308MEDIUMCVSS 5.5EG 5.52023-06-18
A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template Engine. The manipulation leads to deserialization. The exploit has been disclosed to the p…
- CVE-2023-33134HIGHCVSS 8.8EG 8.82023-07-11
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-33160HIGHCVSS 8.8EG 8.82023-07-11
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-3324MEDIUMCVSS 6.3EG 6.32023-07-24
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabil…
- CVE-2023-33284HIGHCVSS 8.8EG 8.82023-06-07
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.
- CVE-2023-33299CRITICALCVSS 9.8EG 9.82023-06-23
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server commun…
- CVE-2023-3343HIGHCVSS 8.8EG 8.82023-07-13
The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with…
- CVE-2023-33496CRITICALCVSS 9.8EG 9.82023-06-07
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
- CVE-2023-3392HIGHCVSS 7.2EG 7.22023-10-16
The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- CVE-2023-33963CRITICALCVSS 9.8EG 9.82023-06-01
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed…
- CVE-2023-34027HIGHCVSS 8.3EG 8.32023-12-19
Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Viewed Products: from n/a through 1.0.0.
- CVE-2023-34040MEDIUMCVSS 5.3EG 5.32023-08-24
In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized objec…
- CVE-2023-34050MEDIUMCVSS 5.0EG 5.02023-10-19
In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; …
- CVE-2023-34052HIGHCVSS 7.8EG 7.82023-10-20
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
- CVE-2023-34212MEDIUMCVSS 6.5EG 6.52023-06-12
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enabl…
- CVE-2023-34347CRITICALCVSS 9.8EG 9.82023-07-10
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
- CVE-2023-34382MEDIUMCVSS 4.4EG 4.42023-12-19
Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – …
- CVE-2023-34434HIGHCVSS 7.5EG 7.52023-07-25
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To s…
- CVE-2023-35084CRITICALCVSS 9.8EG 9.82023-10-18
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.
- CVE-2023-35116HIGHCVSS 4.7EG 7.52023-06-14
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, …
- CVE-2023-3513HIGHCVSS 7.8EG 7.82023-07-14
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user a…
- CVE-2023-35180HIGHCVSS 8.0EG 8.02023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse SolarWinds ARM API.
- CVE-2023-35182HIGHCVSS 8.8EG 8.82023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.
- CVE-2023-35184HIGHCVSS 8.8EG 8.82023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.
- CVE-2023-35186HIGHCVSS 8.0EG 8.02023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.
- CVE-2023-35317HIGHCVSS 7.8EG 7.82023-07-11
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
- CVE-2023-35388HIGHCVSS 8.0EG 8.02023-08-08
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-35669HIGHCVSS 7.8EG 7.82023-09-11
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution priv…
- CVE-2023-35814LOWCVSS 3.5EG 3.52025-04-28
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
- CVE-2023-35815LOWCVSS 3.5EG 3.52025-04-28
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
- CVE-2023-35839CRITICALCVSS 9.8EG 9.82023-06-19
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
- CVE-2023-36035CRITICALCVSS 8.0EG 9.02023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36039HIGHCVSS 8.0EG 8.82023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36050HIGHCVSS 8.0EG 8.22023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36381MEDIUMCVSS 6.6EG 6.62023-12-28
Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.
- CVE-2023-36439HIGHCVSS 8.0EG 8.02023-11-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36480CRITICALCVSS 9.8EG 9.82023-08-04
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects…
- CVE-2023-36736MEDIUMCVSS 4.4EG 4.42023-09-12
Microsoft Identity Linux Broker Remote Code Execution Vulnerability
- CVE-2023-36744HIGHCVSS 8.0EG 8.92023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36745HIGHCVSS 8.0EG 8.92023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36756HIGHCVSS 8.0EG 8.82023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36757HIGHCVSS 8.0EG 8.72023-09-12
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36777HIGHCVSS 5.7EG 8.82023-09-12
Microsoft Exchange Server Information Disclosure Vulnerability
- CVE-2023-36825CRITICALCVSS 9.6EG 9.62023-07-11
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deseria…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →