Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-502 · Deserialization of untrusted dataDefinition on MITRE ↗Clear

70 results·Page 2 / 2

CVE-2021-31010
2022-08-25
Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
Apple

In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.

CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2019-15271
2022-06-08
Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
Cisco

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2021-27852
2022-04-11
Checkbox Survey Deserialization of Untrusted Data Vulnerability
Checkbox

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-42237
2022-03-25
Sitecore XP Remote Command Execution VulnerabilityRansomware
Sitecore

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2019-6340
2022-03-25
Drupal Core Remote Code Execution Vulnerability
Drupal

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2019-10068
2022-03-25
Kentico Xperience Deserialization of Untrusted Data Vulnerability
Kentico

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2018-1000861
2022-02-10
Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
Jenkins

A code execution vulnerability exists in the Stapler web framework used by Jenkins

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2021-44228
2021-12-10
Apache Log4j2 Remote Code Execution VulnerabilityRansomware
Apache

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

CWE-20 · Improper input validationCWE-400CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2021-12-24
CVE-2017-12149
2021-12-10
Red Hat JBoss Application Server Remote Code Execution VulnerabilityRansomware
Red Hat

The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2021-42321
2021-11-17
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

CWE-184CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2021-12-01
CVE-2021-35464
2021-11-03
ForgeRock Access Management (AM) Core Server Remote Code Execution VulnerabilityRansomware
ForgeRock

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-26857
2021-11-03
Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CWE-502 · Deserialization of untrusted data
RefsReference CISA's ED 21-02 (
Federal remediation due 2022-05-03
CVE-2020-7961
2021-11-03
Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay

Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-2555
2021-11-03
Oracle Multiple Products Remote Code Execution Vulnerability
Oracle

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-17144
2021-11-03
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft

Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-10189
2021-11-03
Zoho ManageEngine Desktop Central File Upload Vulnerability
Zoho

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-18935
2021-11-03
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data VulnerabilityRansomware
Progress

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-4939
2021-11-03
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2017-9805
2021-11-03
Apache Struts Deserialization of Untrusted Data Vulnerability
Apache

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2015-4852
2021-11-03
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Oracle

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

CWE-502 · Deserialization of untrusted data
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev2 / 2Next