CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,005 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 7 of 61
- CVE-2019-14439HIGHCVSS 7.5EG 7.52019-07-30
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has…
- CVE-2019-14466MEDIUMCVSS 6.5EG 6.52019-12-31
The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a cr…
- CVE-2019-14540CRITICALCVSS 9.8EG 9.82019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
- CVE-2019-14892CRITICALCVSS 9.8EG 9.82020-03-02
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this…
- CVE-2019-14893CRITICALCVSS 9.8EG 9.82020-03-02
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type…
- CVE-2019-15271CRITICALCVSS 8.8EG 9.0⚠ KEV2019-11-26
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid…
- CVE-2019-15319CRITICALCVSS 9.8EG 9.82019-08-22
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
- CVE-2019-15320CRITICALCVSS 9.8EG 9.82019-08-22
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
- CVE-2019-15321CRITICALCVSS 9.8EG 9.82019-08-22
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
- CVE-2019-15521CRITICALCVSS 9.8EG 9.82019-08-26
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
- CVE-2019-15780CRITICALCVSS 9.8EG 9.82019-08-29
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
- CVE-2019-16112HIGHCVSS 8.8EG 8.82020-05-13
TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.
- CVE-2019-16317HIGHCVSS 8.8EG 8.82019-09-14
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../…
- CVE-2019-16335CRITICALCVSS 9.8EG 9.82019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
- CVE-2019-16755CRITICALCVSS 9.8EG 9.82019-09-26
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted applica…
- CVE-2019-16774MEDIUMCVSS 4.4EG 4.42019-12-12
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
- CVE-2019-16891CRITICALCVSS 9.8EG 9.82019-10-04
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
- CVE-2019-16894CRITICALCVSS 9.8EG 9.82019-09-26
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
- CVE-2019-16942CRITICALCVSS 9.8EG 9.82019-10-01
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commo…
- CVE-2019-16943CRITICALCVSS 9.8EG 9.82019-10-01
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy…
- CVE-2019-17076CRITICALCVSS 9.8EG 9.82020-01-08
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro s…
- CVE-2019-17080HIGHCVSS 7.8EG 7.82019-10-02
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
- CVE-2019-17206CRITICALCVSS 9.8EG 9.82019-10-05
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
- CVE-2019-17267CRITICALCVSS 9.8EG 9.82019-10-07
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
- CVE-2019-17358HIGHCVSS 8.1EG 8.12019-12-12
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions take…
- CVE-2019-17531CRITICALCVSS 9.8EG 9.82019-10-12
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apach…
- CVE-2019-17556CRITICALCVSS 9.8EG 9.82019-12-04
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result …
- CVE-2019-17564CRITICALCVSS 9.8EG 9.82020-04-01
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables…
- CVE-2019-17570CRITICALCVSS 9.8EG 9.82020-01-23
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrar…
- CVE-2019-17571CRITICALCVSS 9.8EG 9.82019-12-20
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network…
- CVE-2019-17635HIGHCVSS 7.8EG 7.82020-01-17
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose…
- CVE-2019-18211HIGHCVSS 8.8EG 8.82019-12-23
An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-p…
- CVE-2019-18283CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by send…
- CVE-2019-18316CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets…
- CVE-2019-18364CRITICALCVSS 9.8EG 9.82019-10-31
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
- CVE-2019-18580CRITICALCVSS 10.0EG 10.02019-11-26
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to e…
- CVE-2019-18601HIGHCVSS 7.5EG 7.52019-10-29
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.
- CVE-2019-18631HIGHCVSS 7.8EG 7.82019-11-05
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially tr…
- CVE-2019-18935CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-11
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017…
- CVE-2019-18956CRITICALCVSS 9.8EG 9.82019-12-17
Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution…
- CVE-2019-19230CRITICALCVSS 9.8EG 9.82019-12-09
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
- CVE-2019-19373HIGHCVSS 7.5EG 7.52019-12-11
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_temp…
- CVE-2019-19470HIGHCVSS 7.8EG 7.82019-12-30
Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.
- CVE-2019-19810CRITICALCVSS 10.0EG 10.02021-10-28
Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary co…
- CVE-2019-19826CRITICALCVSS 9.8EG 9.82019-12-16
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_…
- CVE-2019-19849HIGHCVSS 8.8EG 8.82019-12-17
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires h…
- CVE-2019-19909HIGHCVSS 8.8EG 8.82019-12-19
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a …
- CVE-2019-20330CRITICALCVSS 9.8EG 9.82020-01-03
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
- CVE-2019-20452HIGHCVSS 8.8EG 8.82020-03-17
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An authenticated user with basic privileges can inject objects a…
- CVE-2019-20453HIGHCVSS 8.8EG 8.82020-03-17
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achi…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →