CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (994)
CVE-2023-43981 is a critical deserialization vulnerability in Presto Changeo testsitecreator that allows remote code execution. Attackers can exploit ...
Oct 5, 2023This vulnerability allows remote code execution through deserialization of untrusted data in Schneider Electric products. Attackers can send specially...
Oct 4, 2023CVE-2023-44273 is a signature malleability vulnerability in Consensys gnark-crypto cryptographic library that allows attackers to create multiple vali...
Sep 28, 2023CVE-2023-43291 is a critical deserialization vulnerability in emlog pro CMS that allows remote attackers to execute arbitrary code on affected systems...
Sep 27, 2023This vulnerability in phpPgAdmin allows remote attackers to execute arbitrary code by exploiting insecure deserialization of user-controlled data. Att...
Sep 20, 2023This vulnerability allows remote attackers to execute arbitrary code on Adobe ColdFusion servers without authentication or user interaction. It affect...
Sep 14, 2023CVE-2020-19559 is a critical remote code execution vulnerability in Diebold Aglis XFS for Opteva ATM software. Attackers can execute arbitrary code by...
Sep 11, 2023This vulnerability in knplabs/knp-snappy allows remote code execution through PHAR deserialization when attackers can control the filename parameter i...
Sep 6, 2023This vulnerability allows unauthenticated remote attackers to execute arbitrary code on webMethods OneData servers by exploiting insecure Java RMI des...
Sep 6, 2023CVE-2023-40571 is a critical deserialization vulnerability in weblogic-framework versions 0.2.3 and earlier that allows remote code execution. Attacke...
Aug 25, 2023This vulnerability allows attackers to bypass authentication on Dataprobe iBoot PDU devices by manipulating a cookie's IP address field, redirecting t...
Aug 14, 2023This critical vulnerability in Apache Helix allows remote attackers to execute arbitrary code through unsafe YAML deserialization. Attackers can explo...
Jul 26, 2023This CVE describes a critical Java object deserialization vulnerability in Apache Jackrabbit that allows remote code execution via RMI. Attackers can ...
Jul 25, 2023CVE-2023-38203 is a critical deserialization vulnerability in Adobe ColdFusion that allows attackers to execute arbitrary code without user interactio...
Jul 20, 2023This vulnerability allows attackers to achieve remote code execution by sending specially crafted RabbitMQ messages to Apache EventMesh. The deseriali...
Jul 17, 2023This vulnerability allows attackers to execute arbitrary code on Adobe ColdFusion servers by exploiting insecure deserialization of untrusted data. It...
Jul 12, 2023Delta Electronics InfraSuite Device Master versions before 1.0.7 contain insecure deserialization vulnerabilities that allow remote attackers to execu...
Jul 10, 2023This vulnerability allows remote attackers to execute arbitrary code on Fortinet FortiNAC systems by sending specially crafted requests to the inter-s...
Jun 23, 2023CVE-2023-35839 is a critical deserialization vulnerability in Solon's sofa-hessian component that allows remote attackers to execute arbitrary code by...
Jun 19, 2023The GDPR CCPA Compliance Support plugin for WordPress has a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitr...
Jun 7, 2023The Ultimate Reviews WordPress plugin up to version 2.1.32 contains a PHP object injection vulnerability due to insecure deserialization of untrusted ...
Jun 7, 2023This CVE describes a deserialization vulnerability in DataEase, an open source data visualization tool, that allows remote attackers to execute arbitr...
Jun 1, 2023CVE-2023-27068 is a critical deserialization vulnerability in Sitecore Experience Platform that allows remote attackers to execute arbitrary code via ...
May 23, 2023CVE-2023-31890 is a critical XML deserialization vulnerability in glazedlists v1.11.0 that allows remote attackers to execute arbitrary code by exploi...
May 16, 2023This vulnerability in the AI ChatBot WordPress plugin allows unauthenticated attackers to perform PHP Object Injection by sending specially crafted co...
May 8, 2023Keysight N8844A Data Analytics Web Service contains a deserialization vulnerability that allows remote attackers to execute arbitrary code by sending ...
Apr 27, 2023CVE-2023-20853 is a critical deserialization vulnerability in aEnrich Technology a+HRD's MSMQ asynchronous message processing. Unauthenticated remote ...
Apr 27, 2023CVE-2023-20864 is a critical deserialization vulnerability in VMware Aria Operations for Logs that allows unauthenticated attackers with network acces...
Apr 20, 2023CVE-2021-28254 is a critical deserialization vulnerability in Laravel v8.5.9 that allows attackers to execute arbitrary commands through the destruct(...
Apr 19, 2023This vulnerability in Apache Linkis allows attackers to execute arbitrary code remotely by exploiting a deserialization flaw when configuring MySQL da...
Apr 10, 2023This CVE describes a critical Java insecure deserialization vulnerability in Adobe LiveCycle ES4 that allows unauthenticated remote attackers to execu...
Apr 6, 2023CVE-2020-29312 is a remote code execution vulnerability in Zend Framework versions up to 3.1.3, allowing attackers to execute arbitrary code via insec...
Apr 4, 2023This vulnerability allows remote attackers to execute arbitrary code on Payara Server by exploiting a JNDI rebind operation in the default ORB listene...
Mar 30, 2023This vulnerability in Ivanti Avalanche allows authenticated remote attackers to bypass authentication and execute arbitrary code via insecure deserial...
Mar 29, 2023This vulnerability allows remote attackers to execute arbitrary code on Ivanti Avalanche systems by bypassing authentication and exploiting insecure d...
Mar 29, 2023This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Delta Electronics InfraSuite Device Master systems by sending ...
Mar 27, 2023CVE-2023-26359 is a critical deserialization vulnerability in Adobe ColdFusion that allows attackers to execute arbitrary code without user interactio...
Mar 23, 2023This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites running the vulnerable Lead Generated plugin. Att...
Mar 22, 2023CVE-2023-28115 is a PHAR deserialization vulnerability in the Snappy PHP library that allows attackers to achieve remote code execution by uploading m...
Mar 17, 2023CVE-2023-26779 is a deserialization vulnerability in CleverStupidDog yf-exam version 1.8.0 that allows attackers to execute arbitrary code remotely. T...
Mar 3, 2023CVE-2022-37936 is an unauthenticated Java deserialization vulnerability in HPE Serviceguard Manager that allows remote attackers to execute arbitrary ...
Mar 1, 2023The BuddyForms WordPress plugin before version 2.7.8 contains an unauthenticated insecure deserialization vulnerability. Attackers can exploit this wi...
Feb 23, 2023CVE-2022-47986 is a critical YAML deserialization vulnerability in IBM Aspera Faspex that allows remote attackers to execute arbitrary code on affecte...
Feb 17, 2023This CVE describes a deserialization vulnerability in ThinkPHP framework that allows attackers to execute arbitrary code on affected systems. Attacker...
Feb 8, 2023CVE-2023-25135 is a critical remote code execution vulnerability in vBulletin that allows unauthenticated attackers to execute arbitrary code via craf...
Feb 3, 2023This CVE describes a critical deserialization vulnerability in multiple Mitsubishi Electric industrial control software products. Remote unauthenticat...
Jul 20, 2022CVE-2022-24082 allows remote code execution on Pega Platform installations by exploiting insecure JMX interface exposure. Attackers can upload seriali...
Jul 19, 2022This vulnerability allows unauthenticated attackers to execute arbitrary code on Zoho ManageEngine Password Manager Pro and PAM360 systems through Jav...
Jul 19, 2022This vulnerability in the Feed Them Social WordPress plugin allows unauthenticated attackers to execute arbitrary PHP code via deserialization of untr...
Jul 18, 2022CVE-2022-1660 is a critical deserialization vulnerability that allows unauthenticated remote attackers to execute arbitrary code on affected systems. ...
Jun 2, 2022About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free