CWE-502 · 3 045 записей
Десериализация недоверенных данных
Почему это происходит?
Данные, полученные по сети, десериализуются в собственный объектный формат языка без проверки источника. Во время десериализации могут быть задействованы пути выполнения кода внутри объекта.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
payload = sock.recv(65536)job = pickle.loads(payload)Исправленный код
payload = sock.recv(65536)if not hmac.compare_digest(sign(payload), header_sig): raise PermissionError("недействительная подпись")job = JobSchema.validate(json.loads(payload))Как предотвратить
- 01Для сетевых сообщений используйте форматы, содержащие только данные (например, JSON).
- 02Проверяйте источник сообщения с помощью подписи или взаимного TLS.
- 03Проверяйте десериализованные данные по схеме.
CVE этого класса
3 045 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2025-55182Готовый эксплойт | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Критическая10,0 | KEV | 99,8 % | 3 дек. 2025 г. |
99Срочно | CVE-2021-35464Готовый эксплойт | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.forgerock · access management · CWE-502 | Критическая9,8 | KEV | 100,0 % | 22 июл. 2021 г. |
99Срочно | CVE-2025-53770Готовый эксплойт | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2025 г. |
99Срочно | CVE-2023-29300Готовый эксплойт | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 100,0 % | 12 июл. 2023 г. |
99Срочно | CVE-2025-59287Готовый эксплойт | Windows Server Update Service (WSUS) Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-502 | Критическая9,8 | KEV | 100,0 % | 14 окт. 2025 г. |
99Срочно | CVE-2022-47986Готовый эксплойт | IBM Aspera Faspex code executionibm · aspera faspex · CWE-502 | Критическая9,8 | KEV | 100,0 % | 17 февр. 2023 г. |
99Срочно | CVE-2018-2628Готовый эксплойт | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).oracle · weblogic server · CWE-502 | Критическая9,8 | KEV | 100,0 % | 18 апр. 2018 г. |
99Срочно | CVE-2020-10189Готовый эксплойт | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImagezohocorp · manageengine desktop central · CWE-502 | Критическая9,8 | KEV | 99,9 % | 6 мар. 2020 г. |
99Срочно | CVE-2022-35405Готовый эксплойт | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution.zohocorp · manageengine access manager plus · CWE-502 | Критическая9,8 | KEV | 99,9 % | 19 июл. 2022 г. |
99Срочно | CVE-2020-7961Готовый эксплойт | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web serliferay · liferay portal · CWE-502 | Критическая9,8 | KEV | 99,9 % | 20 мар. 2020 г. |
99Срочно | CVE-2023-46604Готовый эксплойт | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Критическая9,8 | KEV | 99,9 % | 27 окт. 2023 г. |
99Срочно | CVE-2019-18935Готовый эксплойт | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.telerik · ui for asp.net ajax · CWE-502 | Критическая9,8 | KEV | 99,7 % | 11 дек. 2019 г. |
99Срочно | CVE-2017-1000353Готовый эксплойт | Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.jenkins · jenkins · CWE-502 | Критическая9,8 | KEV | 99,7 % | 29 янв. 2018 г. |
98Срочно | CVE-2018-1000861Готовый эксплойт | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/corjenkins · jenkins · CWE-502 | Критическая9,8 | KEV | 98,3 % | 10 дек. 2018 г. |
98Срочно | CVE-2015-7450Готовый эксплойт | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products alloibm · sterling b2b integrator · CWE-502 | Критическая9,8 | KEV | 97,8 % | 2 янв. 2016 г. |
98Срочно | CVE-2021-42237Готовый эксплойт | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achisitecore · experience platform · CWE-502 | Критическая9,8 | KEV | 97,6 % | 5 нояб. 2021 г. |
98Срочно | CVE-2020-2555Готовый эксплойт | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).oracle · access manager · CWE-502 | Критическая9,8 | KEV | 97,1 % | 15 янв. 2020 г. |
98Срочно | CVE-2023-38203Готовый эксплойт | Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCEadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 97,1 % | 20 июл. 2023 г. |
98Срочно | CVE-2015-4852Готовый эксплойт | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitraryoracle · virtual desktop infrastructure · CWE-502 | Критическая9,8 | KEV | 96,0 % | 18 нояб. 2015 г. |
98Срочно | CVE-2019-10068Готовый эксплойт | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.kentico · xperience · CWE-502 | Критическая9,8 | KEV | 95,1 % | 26 мар. 2019 г. |
97Срочно | CVE-2025-24016Готовый эксплойт | Remote code execution in Wazuh serverwazuh · wazuh · CWE-502 | Критическая9,9 | KEV | 93,8 % | 10 февр. 2025 г. |
96Срочно | CVE-2017-12149Готовый эксплойт | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnredhat · jboss enterprise application platform · CWE-502 | Критическая9,8 | KEV | 90,7 % | 4 окт. 2017 г. |
96Срочно | CVE-2017-3066Готовый эксплойт | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializaadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 90,6 % | 27 апр. 2017 г. |
96Срочно | CVE-2024-40711Готовый эксплойт | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).veeam · veeam backup \& replication · CWE-502 | Критическая9,8 | KEV | 90,4 % | 7 сент. 2024 г. |
96Срочно | CVE-2026-63077Готовый эксплойт | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocoljetbrains · teamcity · CWE-502 | Критическая9,8 | KEV | 89,6 % | 27 июл. 2026 г. |
- CVE-2025-55182100Срочно
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %facebook · react3 дек. 2025 г.
- CVE-2021-3546499Срочно
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %forgerock · access management22 июл. 2021 г.
- CVE-2025-5377099Срочно
Microsoft SharePoint Server Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint server19 июл. 2025 г.
- CVE-2023-2930099Срочно
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion12 июл. 2023 г.
- CVE-2025-5928799Срочно
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows server 201214 окт. 2025 г.
- CVE-2022-4798699Срочно
IBM Aspera Faspex code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ibm · aspera faspex17 февр. 2023 г.
- CVE-2018-262899Срочно
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · weblogic server18 апр. 2018 г.
- CVE-2020-1018999Срочно
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine desktop central6 мар. 2020 г.
- CVE-2022-3540599Срочно
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine access manager plus19 июл. 2022 г.
- CVE-2020-796199Срочно
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web ser
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %liferay · liferay portal20 мар. 2020 г.
- CVE-2023-4660499Срочно
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · activemq27 окт. 2023 г.
- CVE-2019-1893599Срочно
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %telerik · ui for asp.net ajax11 дек. 2019 г.
- CVE-2017-100035399Срочно
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %jenkins · jenkins29 янв. 2018 г.
- CVE-2018-100086198Срочно
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %jenkins · jenkins10 дек. 2018 г.
- CVE-2015-745098Срочно
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %ibm · sterling b2b integrator2 янв. 2016 г.
- CVE-2021-4223798Срочно
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %sitecore · experience platform5 нояб. 2021 г.
- CVE-2020-255598Срочно
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · access manager15 янв. 2020 г.
- CVE-2023-3820398Срочно
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %adobe · coldfusion20 июл. 2023 г.
- CVE-2015-485298Срочно
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %oracle · virtual desktop infrastructure18 нояб. 2015 г.
- CVE-2019-1006898Срочно
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %kentico · xperience26 мар. 2019 г.
- CVE-2025-2401697Срочно
Remote code execution in Wazuh server
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 94 %wazuh · wazuh10 февр. 2025 г.
- CVE-2017-1214996Срочно
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 91 %redhat · jboss enterprise application platform4 окт. 2017 г.
- CVE-2017-306696Срочно
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 91 %adobe · coldfusion27 апр. 2017 г.
- CVE-2024-4071196Срочно
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %veeam · veeam backup \& replication7 сент. 2024 г.
- CVE-2026-6307796Срочно
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %jetbrains · teamcity27 июл. 2026 г.