CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,007 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 26 of 61
- CVE-2023-51642CRITICALCVSS 6.3EG 9.82024-11-22
Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to…
- CVE-2023-51656CRITICALCVSS 9.8EG 9.82023-12-21
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
- CVE-2023-51700CRITICALCVSS 9.8EG 9.82023-12-27
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserializati…
- CVE-2023-51785HIGHCVSS 7.5EG 7.52024-01-03
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache I…
- CVE-2023-5183CRITICALCVSS 8.8EG 9.92023-09-27
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoi…
- CVE-2023-52181CRITICALCVSS 9.8EG 10.02023-12-31
Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.
- CVE-2023-52182CRITICALCVSS 8.8EG 9.92023-12-31
Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.
- CVE-2023-52200CRITICALCVSS 9.8EG 9.82024-01-08
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Members…
- CVE-2023-52202CRITICALCVSS 7.2EG 9.12024-01-08
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.
- CVE-2023-52205CRITICALCVSS 7.2EG 9.12024-01-08
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.
- CVE-2023-52206HIGHCVSS 7.2EG 7.72024-01-08
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
- CVE-2023-52207CRITICALCVSS 8.8EG 9.12024-01-08
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.
- CVE-2023-52218CRITICALCVSS 9.8EG 10.02024-01-08
Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.
- CVE-2023-52219CRITICALCVSS 8.8EG 9.92024-01-08
Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.
- CVE-2023-52225CRITICALCVSS 9.8EG 10.02024-01-08
Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a throug…
- CVE-2023-5235HIGHCVSS 8.8EG 8.82024-01-08
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' …
- CVE-2023-52357HIGHCVSS 7.5EG 7.52024-02-18
Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.
- CVE-2023-5391CRITICALCVSS 9.8EG 9.82023-10-04
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
- CVE-2023-5583HIGHCVSS 8.8EG 8.82023-10-30
The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgallery' shortcode. This …
- CVE-2023-6049CRITICALCVSS 9.8EG 9.82024-01-15
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog
- CVE-2023-6378HIGHCVSS 7.5EG 7.52023-11-29
A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.
- CVE-2023-6528HIGHCVSS 8.8EG 8.82024-01-08
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
- CVE-2023-6580HIGHCVSS 8.8EG 8.82023-12-07
A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the component QoS POST Handler. The manipulation of the argument smartqos_express_devices/smart…
- CVE-2023-6654HIGHCVSS 8.8EG 8.82023-12-10
A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to dese…
- CVE-2023-6656HIGHCVSS 7.5EG 7.52023-12-10
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affected by this issue is some unknown functionality of the file DFLIMG/DFLJPG.py. The manipulati…
- CVE-2023-6730HIGHCVSS 8.8EG 8.82023-12-19
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
- CVE-2023-6933CRITICALCVSS 8.8EG 9.82024-02-05
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP O…
- CVE-2023-7018HIGHCVSS 7.8EG 7.82023-12-20
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
- CVE-2023-7032HIGHCVSS 7.8EG 7.82024-01-09
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
- CVE-2023-7064HIGHCVSS 7.5EG 7.52024-05-02
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'aux…
- CVE-2023-7334CRITICALCVSS 9.8EG 9.82026-01-15
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind.…
- CVE-2024-0047MEDIUMCVSS 5.5EG 5.52024-03-11
In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execut…
- CVE-2024-0140MEDIUMCVSS 6.8EG 6.82025-01-28
NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data issue. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and in…
- CVE-2024-0302CRITICALCVSS 9.8EG 9.82024-01-08
A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be ini…
- CVE-2024-0603HIGHCVSS 7.3EG 7.32024-01-16
A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to…
- CVE-2024-0654MEDIUMCVSS 5.3EG 5.32024-01-18
A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads to deserialization. Local access i…
- CVE-2024-0668MEDIUMCVSS 6.6EG 6.62024-02-05
The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for a…
- CVE-2024-0692CRITICALCVSS 8.8EG 9.02024-03-01
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
- CVE-2024-0739HIGHCVSS 7.3EG 7.32024-01-19
A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The manipulation of the argument install leads to deserialization. It is possible…
- CVE-2024-0825HIGHCVSS 8.8EG 8.82024-03-05
The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via deserialization of untrusted input via the vimeography_duplicate_gallery_seria…
- CVE-2024-0936MEDIUMCVSS 6.3EG 6.32024-01-26
A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. The attack c…
- CVE-2024-0937CRITICALCVSS 6.3EG 9.82024-01-26
A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. Th…
- CVE-2024-0959MEDIUMCVSS 5.0EG 5.02024-01-27
A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gibson\utils\pposgd_fuse.py. The manipulation leads to deserialization. It is possible to la…
- CVE-2024-0960MEDIUMCVSS 5.0EG 5.02024-01-27
A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpickle.loads of the file \ai_flow\cli\commands\workflow_command.py. The manipulation leads to …
- CVE-2024-10012HIGHCVSS 7.8EG 7.82024-11-13
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
- CVE-2024-10013HIGHCVSS 7.8EG 7.82024-11-13
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
- CVE-2024-10079HIGHCVSS 8.8EG 8.82024-10-18
The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input from the 'text' parameter in the 'ajax_import_content' function. This allows a…
- CVE-2024-10095HIGHCVSS 8.4EG 8.42024-12-16
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
- CVE-2024-10190CRITICALCVSS 9.8EG 9.82025-03-20
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. S…
- CVE-2024-1032HIGHCVSS 7.3EG 7.32024-01-30
A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of the component Test Connection Handler. Th…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →