Vulnerabilities (CVE)

Filtered by CWE-502
Total 3246 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-63514 1 Microsoft 1 Sharepoint Server 2026-08-12 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-64901 1 Microsoft 1 Sharepoint Server 2026-08-12 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2021-44228 12 Apache, Apple, Bentley and 9 more 166 Log4j, Xcode, Synchro and 163 more 2026-08-11 9.3 HIGH 10.0 CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
CVE-2026-64608 1 Apache 1 Fory 2026-08-11 N/A 9.8 CRITICAL
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not. This issue affects Apache Fory C++: from 0.14.0 before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
CVE-2025-42999 1 Sap 1 Netweaver 2026-08-11 N/A 9.1 CRITICAL
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
CVE-2026-12118 1 Ibm 1 Webmethods Integration 2026-08-10 N/A 9.8 CRITICAL
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
CVE-2024-35249 1 Microsoft 1 Dynamics 365 Business Central 2026-08-10 N/A 8.8 HIGH
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
CVE-2023-38182 1 Microsoft 1 Exchange Server 2026-08-10 N/A 8.0 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-38181 1 Microsoft 1 Exchange Server 2026-08-10 N/A 8.8 HIGH
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-35388 1 Microsoft 1 Exchange Server 2026-08-10 N/A 8.0 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34520 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2026-08-10 6.5 MEDIUM 8.1 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-3989 1 Lmsys 1 Sglang 2026-08-10 N/A 7.8 HIGH
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.
CVE-2026-14890 1 Lmsys 1 Sglang 2026-08-10 N/A 9.1 CRITICAL
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
CVE-2026-71559 1 Apache 1 Fory 2026-08-08 N/A 7.5 HIGH
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
CVE-2026-71558 1 Apache 1 Fory 2026-08-08 N/A 9.8 CRITICAL
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
CVE-2026-71560 1 Apache 1 Fory 2026-08-08 N/A 9.1 CRITICAL
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
CVE-2026-50515 1 Microsoft 1 Azure Service Bus 2026-08-07 N/A 9.9 CRITICAL
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-47623 2 Linux, Nvidia 2 Linux Kernel, Dynamo 2026-08-07 N/A 8.2 HIGH
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-50633 1 Apache 1 Cxf 2026-08-07 N/A 8.1 HIGH
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
CVE-2026-50632 1 Apache 1 Cxf 2026-08-07 N/A 8.1 HIGH
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.