CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,872 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 22 of 58
- CVE-2023-35116MEDIUMCVSS 4.7EG 7.52023-06-14
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, …
- CVE-2023-3513HIGHCVSS 7.8EG 7.82023-07-14
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user a…
- CVE-2023-35180HIGHCVSS 8.0EG 8.02023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse SolarWinds ARM API.
- CVE-2023-35182HIGHCVSS 8.8EG 8.82023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.
- CVE-2023-35184HIGHCVSS 8.8EG 8.82023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.
- CVE-2023-35186HIGHCVSS 8.0EG 8.02023-10-19
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.
- CVE-2023-35317HIGHCVSS 7.8EG 7.82023-07-11
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
- CVE-2023-35388HIGHCVSS 8.0EG 8.02023-08-08
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-35669HIGHCVSS 7.8EG 7.82023-09-11
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution priv…
- CVE-2023-35814LOWCVSS 3.5EG 3.52025-04-28
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
- CVE-2023-35815LOWCVSS 3.5EG 3.52025-04-28
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
- CVE-2023-35839CRITICALCVSS 9.8EG 9.82023-06-19
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
- CVE-2023-36035HIGHCVSS 8.0EG 9.02023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36039HIGHCVSS 8.0EG 8.82023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36050HIGHCVSS 8.0EG 8.22023-11-14
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36381MEDIUMCVSS 6.6EG 6.62023-12-28
Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.
- CVE-2023-36439HIGHCVSS 8.0EG 8.02023-11-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36480CRITICALCVSS 9.8EG 9.82023-08-04
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects…
- CVE-2023-36736MEDIUMCVSS 4.4EG 4.42023-09-12
Microsoft Identity Linux Broker Remote Code Execution Vulnerability
- CVE-2023-36744HIGHCVSS 8.0EG 8.92023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36745HIGHCVSS 8.0EG 8.92023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36756HIGHCVSS 8.0EG 8.82023-09-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-36757HIGHCVSS 8.0EG 8.72023-09-12
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-36777MEDIUMCVSS 5.7EG 8.82023-09-12
Microsoft Exchange Server Information Disclosure Vulnerability
- CVE-2023-36825CRITICALCVSS 9.6EG 9.62023-07-11
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deseria…
- CVE-2023-37227CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
- CVE-2023-37390HIGHCVSS 8.3EG 8.32023-12-19
Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.
- CVE-2023-37895CRITICALCVSS 9.8EG 9.82023-07-25
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-…
- CVE-2023-37941MEDIUMCVSS 6.6EG 6.62023-09-06
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal…
- CVE-2023-38155HIGHCVSS 7.0EG 7.02023-09-12
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-38177MEDIUMCVSS 6.1EG 6.12023-11-14
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-38181HIGHCVSS 8.8EG 8.82023-08-08
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2023-38182HIGHCVSS 8.0EG 8.02023-08-08
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-38203CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-20
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does…
- CVE-2023-38204CRITICALCVSS 9.8EG 9.82023-09-14
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does…
- CVE-2023-38264MEDIUMCVSS 5.9EG 5.92024-05-14
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef an…
- CVE-2023-38647CRITICALCVSS 9.8EG 9.82023-07-26
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can…
- CVE-2023-38689HIGHCVSS 8.1EG 8.12023-08-04
Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `ObjectInputStream#readObject` on untrusted data coming from clients or servers over the network resulting in possible remote …
- CVE-2023-39106HIGHCVSS 8.8EG 8.82023-08-21
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
- CVE-2023-39396HIGHCVSS 7.5EG 7.52023-08-13
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-39410HIGHCVSS 7.5EG 7.52023-09-29
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up …
- CVE-2023-39473HIGHCVSS 8.8EG 8.92024-05-03
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automa…
- CVE-2023-39475CRITICALCVSS 9.8EG 9.82024-05-03
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of I…
- CVE-2023-39476CRITICALCVSS 9.8EG 9.82024-05-03
Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automat…
- CVE-2023-39680HIGHCVSS 7.5EG 7.52023-10-20
Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.
- CVE-2023-39913HIGHCVSS 8.8EG 8.82023-11-08
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommen…
- CVE-2023-40044CRITICALCVSS 10.0EG 10.0⚠ KEV2023-09-27
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
- CVE-2023-40057CRITICALCVSS 9.0EG 9.02024-02-15
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
- CVE-2023-40121MEDIUMCVSS 5.5EG 5.52023-10-27
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp…
- CVE-2023-40195HIGHCVSS 8.8EG 8.82023-08-28
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, a…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →