CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,007 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 24 of 61
- CVE-2023-37227CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
- CVE-2023-37390HIGHCVSS 8.3EG 8.32023-12-19
Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.
- CVE-2023-37895CRITICALCVSS 9.8EG 9.82023-07-25
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-…
- CVE-2023-37941MEDIUMCVSS 6.6EG 6.62023-09-06
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal…
- CVE-2023-38155HIGHCVSS 7.0EG 7.02023-09-12
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-38177MEDIUMCVSS 6.1EG 6.12023-11-14
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-38181HIGHCVSS 8.8EG 8.82023-08-08
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-38182HIGHCVSS 8.0EG 8.02023-08-08
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-38203CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-20
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does…
- CVE-2023-38204CRITICALCVSS 9.8EG 9.82023-09-14
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does…
- CVE-2023-38264MEDIUMCVSS 5.9EG 5.92024-05-14
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef an…
- CVE-2023-38647CRITICALCVSS 9.8EG 9.82023-07-26
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can…
- CVE-2023-38689HIGHCVSS 8.1EG 8.12023-08-04
Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `ObjectInputStream#readObject` on untrusted data coming from clients or servers over the network resulting in possible remote …
- CVE-2023-39106HIGHCVSS 8.8EG 8.82023-08-21
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
- CVE-2023-39396HIGHCVSS 7.5EG 7.52023-08-13
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-39410HIGHCVSS 7.5EG 7.52023-09-29
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up …
- CVE-2023-39473HIGHCVSS 8.8EG 8.92024-05-03
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automa…
- CVE-2023-39475CRITICALCVSS 9.8EG 9.82024-05-03
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of I…
- CVE-2023-39476CRITICALCVSS 9.8EG 9.82024-05-03
Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automat…
- CVE-2023-39680HIGHCVSS 7.5EG 7.52023-10-20
Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.
- CVE-2023-39913HIGHCVSS 8.8EG 8.82023-11-08
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommen…
- CVE-2023-40044CRITICALCVSS 10.0EG 10.0⚠ KEV2023-09-27
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
- CVE-2023-40057CRITICALCVSS 9.0EG 9.02024-02-15
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
- CVE-2023-40121MEDIUMCVSS 5.5EG 5.52023-10-27
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp…
- CVE-2023-40195HIGHCVSS 8.8EG 8.82023-08-28
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, a…
- CVE-2023-40555HIGHCVSS 8.3EG 8.32023-12-20
Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.
- CVE-2023-40571CRITICALCVSS 9.8EG 9.82023-08-25
weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-fram…
- CVE-2023-40595HIGHCVSS 8.8EG 8.82023-08-30
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.
- CVE-2023-40619CRITICALCVSS 9.8EG 9.82023-09-20
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is …
- CVE-2023-41330CRITICALCVSS 9.8EG 9.82023-09-06
knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution throug…
- CVE-2023-42809HIGHCVSS 8.8EG 8.82023-10-04
Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client deserializes without further validation. Attackers that manage…
- CVE-2023-4314HIGHCVSS 7.2EG 7.22023-09-11
The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows admins to deserialize arbitrary data which may lead to remote code execution if a suitable g…
- CVE-2023-43176HIGHCVSS 8.8EG 8.82023-10-03
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
- CVE-2023-43208CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-26
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
- CVE-2023-43268HIGHCVSS 8.8EG 8.82023-10-02
Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.
- CVE-2023-43291CRITICALCVSS 9.8EG 9.82023-09-27
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
- CVE-2023-4386HIGHCVSS 8.1EG 8.12023-10-20
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP…
- CVE-2023-43981CRITICALCVSS 9.8EG 9.82023-10-05
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.
- CVE-2023-4402CRITICALCVSS 9.8EG 9.82023-10-20
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a …
- CVE-2023-44273CRITICALCVSS 9.8EG 9.82023-09-28
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
- CVE-2023-44350CRITICALCVSS 9.8EG 9.82023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user int…
- CVE-2023-44351CRITICALCVSS 9.8EG 9.82023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user int…
- CVE-2023-44353CRITICALCVSS 9.8EG 9.82023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user int…
- CVE-2023-44392CRITICALCVSS 9.0EG 9.02023-10-09
Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library, which is vulnerable to code injection due to an insecure implementation of deserializati…
- CVE-2023-45146CRITICALCVSS 10.0EG 10.02023-10-18
XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the ser…
- CVE-2023-45185HIGHCVSS 8.8EG 8.82023-12-14
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IB…
- CVE-2023-4528HIGHCVSS 7.2EG 7.22023-09-07
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
- CVE-2023-45672HIGHCVSS 7.5EG 7.52023-10-30
Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpoints used to save configurations for Frigate. This can lead to unauthenticated remote code…
- CVE-2023-46147HIGHCVSS 8.8EG 8.82023-12-20
Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
- CVE-2023-46154HIGHCVSS 7.2EG 7.22023-12-19
Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →