Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-502 · Deserialization of untrusted dataDefinition on MITRE ↗Clear

70 results·Page 1 / 2

CVE-2026-63077
2026-08-05
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
JetBrains

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

CWE-502 · Deserialization of untrusted data
Refsblog.jetbrains.comjetbrains.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-08
CVE-2026-50522
2026-07-22
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-25
CVE-2026-58644
2026-07-16
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-19
CVE-2026-45659
2026-07-01
Microsoft SharePoint Server Deserialization of Untrusted Data VulnerabilityRansomware
Microsoft

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-04
CVE-2026-12569
2026-06-25
PTC Windchill and FlexPLM Improper Input Validation VulnerabilityRansomware
PTC

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
Refsptc.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-28
CVE-2026-45247
2026-06-03
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

CWE-502 · Deserialization of untrusted data
Refsmirasvit.comnvd.nist.gov
Federal remediation due 2026-06-06
CVE-2023-21529
2026-04-13
Microsoft Exchange Server Deserialization of Untrusted Data VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-04-27
CVE-2026-20131
2026-03-19
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityRansomware
Cisco

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

CWE-502 · Deserialization of untrusted data
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2026-03-22
CVE-2026-20963
2026-03-18
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-03-21
CVE-2025-26399
2026-03-09
SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityRansomware
SolarWinds

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

CWE-502 · Deserialization of untrusted data
Refssolarwinds.comdocumentation.solarwinds.comnvd.nist.gov
Federal remediation due 2026-03-12
CVE-2025-49113
2026-02-20
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Roundcube

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

CWE-502 · Deserialization of untrusted data
Refsroundcube.netgithub.comgithub.comnvd.nist.gov
Federal remediation due 2026-03-13
CVE-2025-40551
2026-02-03
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

CWE-502 · Deserialization of untrusted data
Refssolarwinds.comnvd.nist.gov
Federal remediation due 2026-02-06
CVE-2025-59287
2025-10-24
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Microsoft

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-14
CVE-2025-10035
2025-09-29
Fortra GoAnywhere MFT Deserialization of Untrusted Data VulnerabilityRansomware
Fortra

Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CWE-502 · Deserialization of untrusted dataCWE-77 · Command injection
Refsfortra.comnvd.nist.gov
Federal remediation due 2025-10-20
CVE-2025-5086
2025-09-11
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
Dassault Systèmes

Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.

CWE-502 · Deserialization of untrusted data
Refs3ds.comnvd.nist.gov
Federal remediation due 2025-10-02
CVE-2025-53690
2025-09-04
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Sitecore

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

CWE-502 · Deserialization of untrusted data
Refssupport.sitecore.comnvd.nist.gov
Federal remediation due 2025-09-25
CVE-2024-8069
2025-08-25
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

CWE-502 · Deserialization of untrusted data
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2025-09-15
CVE-2025-53770
2025-07-20
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityRansomware
Microsoft

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

CWE-502 · Deserialization of untrusted data
RefsCISA Mitigation Instructionsmicrosoft.commsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-07-21
CVE-2025-24016
2025-06-10
Wazuh Server Deserialization of Untrusted Data Vulnerability
Wazuh

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

CWE-502 · Deserialization of untrusted data
Refswazuh.comgithub.comnvd.nist.gov
Federal remediation due 2025-07-01
CVE-2025-42999
2025-05-15
SAP NetWeaver Deserialization VulnerabilityRansomware
SAP

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

CWE-502 · Deserialization of untrusted data
RefsSAP users must have an account to log in and access the patchnvd.nist.gov
Federal remediation due 2025-06-05
CVE-2025-24813
2025-04-01
Apache Tomcat Path Equivalence Vulnerability
Apache

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.

CWE-44CWE-502 · Deserialization of untrusted data
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2025-04-22
CVE-2019-9875
2025-03-26
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Sitecore

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

CWE-502 · Deserialization of untrusted data
Refssupport.sitecore.comnvd.nist.gov
Federal remediation due 2025-04-16
CVE-2019-9874
2025-03-26
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Sitecore

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

CWE-502 · Deserialization of untrusted data
Refssupport.sitecore.comnvd.nist.gov
Federal remediation due 2025-04-16
CVE-2024-20953
2025-02-24
Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Oracle

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

CWE-502 · Deserialization of untrusted data
Refsoracle.comnvd.nist.gov
Federal remediation due 2025-03-17
CVE-2017-3066
2025-02-24
Adobe ColdFusion Deserialization Vulnerability
Adobe

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

CWE-502 · Deserialization of untrusted data
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2025-03-17
CVE-2025-0994
2025-02-07
Trimble Cityworks Deserialization Vulnerability
Trimble

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.

CWE-502 · Deserialization of untrusted data
Refslearn.assetlifecycle.trimble.comcisa.govnvd.nist.gov
Federal remediation due 2025-02-28
CVE-2025-23006
2025-01-24
SonicWall SMA1000 Appliances Deserialization VulnerabilityRansomware
SonicWall

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

CWE-502 · Deserialization of untrusted data
Refspsirt.global.sonicwall.comnvd.nist.gov
Federal remediation due 2025-02-14
CVE-2024-38094
2024-10-22
Microsoft SharePoint Deserialization VulnerabilityRansomware
Microsoft

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-11-12
CVE-2024-40711
2024-10-17
Veeam Backup and Replication Deserialization VulnerabilityRansomware
Veeam / Backup & Replication

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

CWE-502 · Deserialization of untrusted data
Refsveeam.comnvd.nist.gov
Federal remediation due 2024-11-07
CVE-2019-0344
2024-09-30
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.

CWE-502 · Deserialization of untrusted data
Refsweb.archive.orgnvd.nist.gov
Federal remediation due 2024-10-21
CVE-2022-21445
2024-09-18
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Oracle

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

CWE-502 · Deserialization of untrusted data
Refsoracle.comnvd.nist.gov
Federal remediation due 2024-10-09
CVE-2020-0618
2024-09-18
Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-10-09
CVE-2024-28986
2024-08-15
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

CWE-502 · Deserialization of untrusted data
Refssolarwinds.comnvd.nist.gov
Federal remediation due 2024-09-05
CVE-2018-0824
2024-08-05
Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Microsoft

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.

CWE-502 · Deserialization of untrusted data
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-08-26
CVE-2023-43208
2024-05-20
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data VulnerabilityRansomware
NextGen Healthcare

NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.

CWE-502 · Deserialization of untrusted data
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-06-10
CVE-2018-15133
2024-01-16
Laravel Deserialization of Untrusted Data Vulnerability
Laravel / Laravel Framework

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

CWE-502 · Deserialization of untrusted data
Refslaravel.comnvd.nist.gov
Federal remediation due 2024-02-06
CVE-2023-38203
2024-01-08
Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityRansomware
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

CWE-502 · Deserialization of untrusted data
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-29300
2024-01-08
Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityRansomware
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

CWE-502 · Deserialization of untrusted data
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-46604
2023-11-02
Apache ActiveMQ Deserialization of Untrusted Data VulnerabilityRansomware
Apache

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

CWE-502 · Deserialization of untrusted data
Refsactivemq.apache.orgnvd.nist.gov
Federal remediation due 2023-11-23
CVE-2023-40044
2023-10-05
Progress WS_FTP Server Deserialization of Untrusted Data VulnerabilityRansomware
Progress

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

CWE-502 · Deserialization of untrusted data
Refscommunity.progress.comnvd.nist.gov
Federal remediation due 2023-10-26
CVE-2023-26359
2023-08-21
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.

CWE-502 · Deserialization of untrusted data
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-09-11
CVE-2022-31199
2023-07-11
Netwrix Auditor Insecure Object Deserialization VulnerabilityRansomware
Netwrix

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

CWE-502 · Deserialization of untrusted dataCWE-122 · Heap buffer overflow
RefsPatch application requires login to customer portalnvd.nist.gov
Federal remediation due 2023-08-01
CVE-2021-39144
2023-03-10
XStream Remote Code Execution Vulnerability
XStream

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

CWE-94 · Code injectionCWE-502 · Deserialization of untrusted data
Refsvmware.comnvd.nist.gov
Federal remediation due 2023-03-31
CVE-2020-5741
2023-03-10
Plex Media Server Remote Code Execution Vulnerability
Plex

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

CWE-502 · Deserialization of untrusted data
Refsforums.plex.tvnvd.nist.gov
Federal remediation due 2023-03-31
CVE-2022-47986
2023-02-21
IBM Aspera Faspex Code Execution VulnerabilityRansomware
IBM

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

CWE-502 · Deserialization of untrusted data
Refsexchange.xforce.ibmcloud.comnvd.nist.gov
Federal remediation due 2023-03-14
CVE-2023-0669
2023-02-10
Fortra GoAnywhere MFT Remote Code Execution VulnerabilityRansomware
Fortra

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

CWE-502 · Deserialization of untrusted data
RefsThis CVE has a CISA AA located herenvd.nist.gov
Federal remediation due 2023-03-03
CVE-2021-35587
2022-11-28
Oracle Fusion Middleware Unspecified Vulnerability
Oracle

Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.

CWE-502 · Deserialization of untrusted dataCWE-790
Refsoracle.comnvd.nist.gov
Federal remediation due 2022-12-19
CVE-2022-41082
2022-09-30
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.

CWE-502 · Deserialization of untrusted data
Refsmsrc-blog.microsoft.comnvd.nist.gov
Federal remediation due 2022-10-21
CVE-2022-35405
2022-09-22
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Zoho

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsmanageengine.comnvd.nist.gov
Federal remediation due 2022-10-13
CVE-2018-2628
2022-09-08
Oracle WebLogic Server Unspecified Vulnerability
Oracle

Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.

CWE-502 · Deserialization of untrusted data
Refsoracle.comnvd.nist.gov
Federal remediation due 2022-09-29
Prev1 / 2Next