CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Yearly Trend
Top Affected Vendors
All Deserialization of Untrusted Data CVEs (994)
This vulnerability allows unauthenticated remote code execution on Siemens Healthineers medical imaging systems through insecure deserialization of un...
Jun 1, 2022CVE-2022-24108 is a critical insecure deserialization vulnerability in the Skyoftech So Listing Tabs module for OpenCart. It allows remote attackers t...
May 17, 2022CVE-2022-29363 is a critical deserialization vulnerability in Phpok v6.1 that allows unauthenticated attackers to execute arbitrary code by writing ma...
May 12, 2022This vulnerability allows remote attackers to execute arbitrary code on Orlansoft ERP systems by sending malicious serialized Java objects to the Java...
May 2, 2022CVE-2022-25767 is a critical remote code execution vulnerability in the uReport2 console component. It allows attackers to execute arbitrary code by t...
May 1, 2022CVE-2022-29528 is a PHAR deserialization vulnerability in MISP (Malware Information Sharing Platform) that allows attackers to execute arbitrary code ...
Apr 20, 2022This vulnerability allows remote, unauthenticated attackers to execute arbitrary code on Atlassian Bitbucket Data Center instances via Java deserializ...
Apr 20, 2022CVE-2022-21445 is a critical deserialization vulnerability in Oracle ADF Faces that allows unauthenticated remote attackers to execute arbitrary code....
Apr 19, 2022This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on affected SIMATIC Energy Manager systems...
Apr 12, 2022CVE-2020-19229 is a critical vulnerability in Jeesite 1.2.7 that uses a vulnerable version of Apache Shiro (1.2.3). This allows attackers to exploit a...
Apr 5, 2022CVE-2021-33207 is a critical deserialization vulnerability in MashZone NextGen's HTTP client that allows remote code execution when processing HTTP re...
Apr 5, 2022A deserialization vulnerability in Apache Dubbo's Hessian-lite serialization protocol allows remote attackers to execute arbitrary code by sending spe...
Jan 10, 2022CVE-2021-42392 is a critical remote code execution vulnerability in H2 Database where attackers can exploit JNDI injection through the database driver...
Jan 10, 2022CVE-2021-44029 is a remote code execution vulnerability in Quest KACE Desktop Authority versions before 11.2, caused by insecure deserialization in th...
Dec 22, 2021CVE-2021-36336 is a critical deserialization vulnerability in Wyse Management Suite that allows unauthenticated attackers to execute arbitrary code on...
Dec 21, 2021This vulnerability allows remote attackers to execute arbitrary code on Ivanti Avalanche systems by sending maliciously crafted data to the Data Repos...
Dec 7, 2021This vulnerability allows remote code execution on Veritas Enterprise Vault servers through insecure .NET Remoting services. Attackers can exploit des...
Dec 6, 2021This vulnerability allows remote code execution on Veritas Enterprise Vault servers through insecure .NET Remoting TCP ports. Attackers can exploit de...
Dec 6, 2021This vulnerability in Veritas Enterprise Vault allows remote code execution through insecure .NET Remoting services that deserialize untrusted data. A...
Dec 6, 2021ThinkPHP v6.0.8 contains a deserialization vulnerability in the Flysystem cached adapter component that allows remote code execution. Attackers can ex...
Dec 6, 2021CVE-2021-42237 is a critical remote code execution vulnerability in Sitecore Experience Platform (XP) that allows unauthenticated attackers to execute...
Nov 5, 2021CVE-2021-40719 is a critical deserialization vulnerability in Adobe Connect that allows attackers to execute arbitrary code on affected servers by sen...
Oct 21, 2021CVE-2021-40720 is a critical deserialization vulnerability in Adobe Ops CLI that allows arbitrary code execution when processing malicious files. Atta...
Oct 15, 2021CVE-2021-42090 is a remote code execution vulnerability in Zammad's Form functionality due to unsafe deserialization. Attackers can execute arbitrary ...
Oct 7, 2021CVE-2021-41616 is a critical deserialization vulnerability in Apache DB DdlUtils 1.0 that allows remote code execution by exploiting insecure ObjectIn...
Sep 30, 2021CVE-2021-31819 is a deserialization vulnerability in Halibut versions before 4.4.7 that allows remote code execution on systems that already trust eac...
Sep 22, 2021CVE-2021-39392 is a critical remote code execution vulnerability in MyLittleBackup management tool due to a hardcoded machineKey in web.config. This a...
Sep 15, 2021Apache Dubbo's Hessian protocol implementation has a critical deserialization vulnerability that allows unauthenticated remote code execution. Attacke...
Sep 7, 2021CVE-2021-21741 is a critical remote code execution vulnerability in ZTE conference management systems where attackers can execute arbitrary commands b...
Aug 30, 2021CVE-2021-37544 is an insecure deserialization vulnerability in JetBrains TeamCity that allows remote attackers to execute arbitrary code on affected s...
Aug 6, 2021This vulnerability allows remote code execution on Neo4j databases with the shell server enabled. Attackers can exploit Java deserialization in the ex...
Aug 5, 2021CVE-2021-29781 is a critical remote code execution vulnerability in IBM Partner Engagement Manager 2.0 caused by unsafe deserialization. Attackers can...
Jul 30, 2021CVE-2021-37578 is a Java deserialization vulnerability in Apache jUDDI's RMI implementation that allows remote code execution. Attackers can send mali...
Jul 29, 2021This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Dell EMC Avamar Server and Integrated Data Protection Applianc...
Jul 28, 2021CVE-2021-35464 is an unauthenticated remote code execution vulnerability in ForgeRock AM servers due to insecure Java deserialization in the jato.page...
Jul 22, 2021This vulnerability in Veeam Backup and Replication allows remote attackers to execute arbitrary code via insecure .NET remoting deserialization. It af...
Jun 30, 2021CVE-2020-9493 is a critical deserialization vulnerability in Apache Chainsaw that allows remote attackers to execute arbitrary code by sending special...
Jun 16, 2021CVE-2021-33806 is a remote code execution vulnerability in the BDew BdLib library for Minecraft, caused by insecure deserialization of untrusted data....
Jun 3, 2021CVE-2021-25641 is a critical deserialization vulnerability in Apache Dubbo that allows remote unauthenticated attackers to force servers to use insecu...
Jun 1, 2021CVE-2021-30179 is a critical remote code execution vulnerability in Apache Dubbo that allows attackers to execute arbitrary Java code by exploiting in...
Jun 1, 2021CVE-2021-33790 is a critical deserialization vulnerability in the RebornCore library for Minecraft mods that allows remote code execution. Attackers c...
May 31, 2021This vulnerability allows unauthenticated remote attackers to execute arbitrary code on systems running vulnerable versions of Checkbox Survey. It aff...
May 27, 2021CVE-2021-32075 is an insecure deserialization vulnerability in Re-Logic Terraria game client that allows remote code execution. Attackers can exploit ...
May 24, 2021This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on SolarWinds Network Performance Monitor ...
May 21, 2021CVE-2021-32098 is a critical vulnerability in Artica Pandora FMS that allows unauthenticated attackers to perform Phar deserialization, potentially le...
May 7, 2021This vulnerability in PHPMailer allows remote attackers to execute arbitrary code through object injection via Phar deserialization when using UNC pat...
Apr 28, 2021CVE-2021-29476 is a deserialization vulnerability in the PHP Requests HTTP library that allows remote code execution. Attackers can exploit this by se...
Apr 27, 2021CVE-2021-29200 is an unsafe deserialization vulnerability in Apache OFBiz that allows unauthenticated remote code execution. Attackers can exploit thi...
Apr 27, 2021Apache OFBiz versions before 17.12.07 contain an unsafe deserialization vulnerability that allows remote attackers to execute arbitrary code on affect...
Apr 27, 2021CVE-2021-3287 is an unauthenticated remote code execution vulnerability in Zoho ManageEngine OpManager caused by insecure Java deserialization. Attack...
Apr 22, 2021About Deserialization of Untrusted Data (CWE-502)
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Our database tracks 994 CVEs classified as CWE-502, with 480 rated critical and 458 rated high severity. The average CVSS score for Deserialization of Untrusted Data vulnerabilities is 8.8.
External reference: View CWE-502 on MITRE CWE →
Monitor Deserialization of Untrusted Data Vulnerabilities
Get alerted when new Deserialization of Untrusted Data CVEs affect your infrastructure.
Start Monitoring Free