CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 30 of 61
- CVE-2024-28991CRITICALCVSS 9.0EG 9.02024-09-12
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.
- CVE-2024-29032MEDIUMCVSS 5.3EG 5.32024-03-20
Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and prior to version 0.21.2, deserializing json data using `qisk…
- CVE-2024-29040MEDIUMCVSS 4.3EG 4.32024-06-28
This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the…
- CVE-2024-29136HIGHCVSS 8.5EG 8.52024-03-19
Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.
- CVE-2024-29212CRITICALCVSS 9.9EG 9.92024-05-14
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (…
- CVE-2024-29433CRITICALCVSS 9.8EG 9.82024-04-01
A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.
- CVE-2024-29800HIGHCVSS 8.0EG 8.02024-05-14
Deserialization of Untrusted Data vulnerability in Timber Team & Contributors Timber.This issue affects Timber: from n/a through 1.23.0.
- CVE-2024-29847CRITICALCVSS 9.8EG 10.02024-09-12
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
- CVE-2024-30042HIGHCVSS 7.8EG 7.82024-05-14
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2024-30044CRITICALCVSS 7.2EG 9.02024-05-14
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2024-3018HIGHCVSS 8.8EG 8.82024-03-30
The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Regi…
- CVE-2024-3020HIGHCVSS 7.2EG 7.22024-04-10
The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function via the 'shortcode' parameter. This allows authenticated attackers, with administrator-le…
- CVE-2024-30221MEDIUMCVSS 5.4EG 5.42024-03-28
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.
- CVE-2024-30222HIGHCVSS 8.5EG 8.52024-03-28
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.
- CVE-2024-30223CRITICALCVSS 9.0EG 9.02024-03-28
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.
- CVE-2024-30224CRITICALCVSS 10.0EG 10.02024-03-28
Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.
- CVE-2024-30225CRITICALCVSS 10.0EG 10.02024-03-28
Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.
- CVE-2024-30226CRITICALCVSS 9.0EG 9.02024-03-28
Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.
- CVE-2024-30227CRITICALCVSS 9.0EG 9.02024-03-28
Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.
- CVE-2024-30228CRITICALCVSS 9.9EG 9.92024-03-28
Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.
- CVE-2024-30229HIGHCVSS 8.0EG 8.02024-03-28
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.
- CVE-2024-30230HIGHCVSS 8.2EG 8.22024-03-28
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.
- CVE-2024-3054HIGHCVSS 7.2EG 7.62024-04-12
WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to…
- CVE-2024-3070CRITICALCVSS 9.8EG 9.82024-05-14
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for u…
- CVE-2024-31094CRITICALCVSS 8.5EG 9.82024-03-31
Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
- CVE-2024-31211MEDIUMCVSS 5.5EG 5.52024-04-04
WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. V…
- CVE-2024-31224CRITICALCVSS 9.8EG 9.82024-04-08
GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution.…
- CVE-2024-31277HIGHCVSS 8.7EG 8.72024-04-07
Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.
- CVE-2024-31308MEDIUMCVSS 4.4EG 4.42024-04-07
Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.
- CVE-2024-31317HIGHCVSS 7.8EG 7.82024-07-09
In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privile…
- CVE-2024-31879HIGHCVSS 7.5EG 7.52024-05-18
IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.
- CVE-2024-31903HIGHCVSS 8.8EG 8.82025-01-22
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
- CVE-2024-32030HIGHCVSS 8.1EG 8.22024-06-19
Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port. As a separate feature, it also provides the ability to monitor the…
- CVE-2024-3240HIGHCVSS 8.8EG 8.82024-05-04
The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_info_bar' shortcode. This ma…
- CVE-2024-32431MEDIUMCVSS 4.4EG 4.42024-04-15
Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2.
- CVE-2024-32600HIGHCVSS 8.3EG 8.32024-04-18
Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.
- CVE-2024-32603HIGHCVSS 8.5EG 8.52024-04-18
Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.
- CVE-2024-32817MEDIUMCVSS 4.4EG 4.42024-04-24
Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2.
- CVE-2024-32835MEDIUMCVSS 5.4EG 5.42024-04-24
Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3.
- CVE-2024-32876HIGHCVSS 8.5EG 8.52024-04-24
NewPipe is an Android app for video streaming written in Java. It supports exporting and importing backups, as a way to let users move their data to a new device effortlessly. However, in versions 0.13.4 through 0.26.1, importing a backup …
- CVE-2024-3300CRITICALCVSS 9.0EG 9.02024-05-30
An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.
- CVE-2024-3301HIGHCVSS 8.5EG 8.52024-05-30
An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.
- CVE-2024-33553CRITICALCVSS 9.0EG 9.02024-04-29
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
- CVE-2024-33568HIGHCVSS 8.5EG 8.52024-06-04
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from …
- CVE-2024-33641MEDIUMCVSS 5.4EG 5.42024-04-29
Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3.
- CVE-2024-3366LOWCVSS 3.5EG 3.52024-04-06
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipula…
- CVE-2024-34072HIGHCVSS 7.8EG 7.82024-05-03
sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted da…
- CVE-2024-34075MEDIUMCVSS 6.2EG 6.22024-05-03
kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method used in `Markov#generate` and `Markov#choose` allows a maliciously crafted string on the da…
- CVE-2024-34274LOWCVSS 3.9EG 3.92024-05-21
OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vu…
- CVE-2024-3431MEDIUMCVSS 4.7EG 4.72024-04-07
A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&c=Field&a=channel_edit of the component Backend. The manipulation of the argument channel_…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →