CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,009 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 32 of 61
- CVE-2024-4157HIGHCVSS 7.5EG 7.52024-05-22
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the…
- CVE-2024-41874CRITICALCVSS 9.8EG 9.82024-09-13
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabilit…
- CVE-2024-4200HIGHCVSS 7.7EG 7.72024-05-15
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
- CVE-2024-42323HIGHCVSS 8.8EG 8.82024-09-21
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommen…
- CVE-2024-42362HIGHCVSS 8.8EG 8.82024-08-20
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.
- CVE-2024-42363HIGHCVSS 8.8EG 8.82024-08-20
Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method wher…
- CVE-2024-43080HIGHCVSS 7.8EG 7.82024-11-13
In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2024-43141CRITICALCVSS 9.8EG 9.82024-08-13
Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.
- CVE-2024-43191HIGHCVSS 7.2EG 7.22024-09-26
IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.
- CVE-2024-43242CRITICALCVSS 9.0EG 9.02024-08-19
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
- CVE-2024-43252CRITICALCVSS 9.0EG 9.02024-08-19
Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.
- CVE-2024-43354CRITICALCVSS 9.8EG 9.82024-08-19
Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
- CVE-2024-43383HIGHCVSS 8.0EG 8.02024-10-31
Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a re…
- CVE-2024-43464HIGHCVSS 7.2EG 7.42024-09-10
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2024-43466MEDIUMCVSS 6.5EG 6.52024-09-10
Microsoft SharePoint Server Denial of Service Vulnerability
- CVE-2024-4371CRITICALCVSS 9.0EG 9.02024-06-13
The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted i…
- CVE-2024-43931CRITICALCVSS 9.8EG 9.82024-08-29
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
- CVE-2024-44102CRITICALCVSS 10.0EG 10.02024-11-12
A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1) (All versions…
- CVE-2024-4413CRITICALCVSS 9.8EG 9.82024-05-14
The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Obj…
- CVE-2024-4471HIGHCVSS 8.0EG 8.02024-05-23
The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.3.1 via deserialization of untrusted input in the 'export_content' function. This allows authen…
- CVE-2024-44902CRITICALCVSS 9.8EG 9.82024-09-09
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
- CVE-2024-45084HIGHCVSS 8.0EG 8.02025-02-19
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of fi…
- CVE-2024-45733HIGHCVSS 8.8EG 8.82024-10-14
In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.
- CVE-2024-45758CRITICALCVSS 9.1EG 9.12024-09-06
H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with …
- CVE-2024-45772MEDIUMCVSS 5.1EG 5.12024-09-30
Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apa…
- CVE-2024-45852HIGHCVSS 8.8EG 8.82024-09-12
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
- CVE-2024-45853HIGHCVSS 7.1EG 7.12024-09-12
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.
- CVE-2024-45854HIGHCVSS 7.1EG 7.12024-09-12
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.
- CVE-2024-45855HIGHCVSS 7.1EG 7.12024-09-12
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.
- CVE-2024-45857HIGHCVSS 7.8EG 7.82024-09-12
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.
- CVE-2024-4606MEDIUMCVSS 5.4EG 5.42024-05-14
Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.0.3.
- CVE-2024-4699MEDIUMCVSS 6.3EG 6.32024-05-14
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argumen…
- CVE-2024-47072HIGHCVSS 7.5EG 7.52024-11-08
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the proce…
- CVE-2024-47074CRITICALCVSS 9.8EG 9.82024-10-11
DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/jav…
- CVE-2024-47092CRITICALCVSS 9.8EG 9.82025-03-03
Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1
- CVE-2024-4733HIGHCVSS 7.5EG 7.52024-05-16
The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenti…
- CVE-2024-47552CRITICALCVSS 9.8EG 9.82025-03-20
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Severity Justification: The Apache Seata security team assesses the severity of…
- CVE-2024-47561HIGHCVSS 7.3EG 7.32024-10-03
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
- CVE-2024-47636CRITICALCVSS 9.8EG 9.82024-10-10
Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.
- CVE-2024-47836LOWCVSS 3.5EG 3.52024-10-16
Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.
- CVE-2024-47886HIGHCVSS 7.2EG 7.22026-03-02
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtua…
- CVE-2024-48026CRITICALCVSS 9.8EG 9.82024-10-16
Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.
- CVE-2024-48028CRITICALCVSS 9.8EG 9.82024-10-16
Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.
- CVE-2024-48030CRITICALCVSS 9.8EG 9.82024-10-16
Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.
- CVE-2024-48033CRITICALCVSS 9.8EG 9.82024-10-11
Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.
- CVE-2024-48063CRITICALCVSS 9.8EG 9.82024-10-29
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
- CVE-2024-48112CRITICALCVSS 9.8EG 9.82024-10-30
A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
- CVE-2024-48206CRITICALCVSS 9.8EG 9.82024-10-29
A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.
- CVE-2024-4838HIGHCVSS 7.5EG 8.82024-05-16
The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes…
- CVE-2024-49063HIGHCVSS 8.4EG 8.42024-12-12
Microsoft/Muzic Remote Code Execution Vulnerability
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →