CWE-502 可信数据的反序列化 类弱点 2188 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }
private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }
try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-24601 | WordPress plugin FundPress 代码问题漏洞 — FundPress | 9.8 | Critical | 2025-01-27 |
| CVE-2024-12600 | WordPress plugin Custom Product Tabs Lite for WooCommerce 代码问题漏洞 — Custom Product Tabs Lite for WooCommerce | 7.2 | High | 2025-01-25 |
| CVE-2025-23006 | SonicWALL SMA1000 代码问题漏洞 — SMA1000 | 9.8 | - | 2025-01-23 |
| CVE-2024-31903 | IBM Sterling B2B Integrator 代码问题漏洞 — Sterling B2B Integrator Standard Edition | 8.8 | High | 2025-01-22 |
| CVE-2025-23914 | WordPress plugin Muzaara Google Ads Report 代码问题漏洞 — Muzaara Google Ads Report | 9.8 | Critical | 2025-01-22 |
| CVE-2025-23944 | WordPress plugin WOOEXIM 代码问题漏洞 — WOOEXIM | 8.8 | High | 2025-01-22 |
| CVE-2025-23932 | WordPress plugin Quick Count 代码问题漏洞 — Quick Count | 9.8 | Critical | 2025-01-22 |
| CVE-2025-0429 | WordPress plugin AI Power 代码问题漏洞 — AI Puffer – Your AI engine for WordPress (formerly AI Power) | 7.2 | High | 2025-01-22 |
| CVE-2025-0428 | WordPress plugin AI Power 代码问题漏洞 — AI Puffer – Your AI engine for WordPress (formerly AI Power) | 7.2 | High | 2025-01-22 |
| CVE-2024-49699 | WordPress plugin ARPrice 代码问题漏洞 — ARPrice | 8.8 | High | 2025-01-21 |
| CVE-2024-49688 | WordPress plugin ARPrice 代码问题漏洞 — ARPrice | 9.8 | Critical | 2025-01-21 |
| CVE-2024-10936 | WordPress plugin String locator 代码问题漏洞 — String locator | 8.8 | High | 2025-01-21 |
| CVE-2025-0586 | aEnrich a+HRD 代码问题漏洞 — a+HRD | 7.2 | High | 2025-01-20 |
| CVE-2024-12703 | Schneider Electric RemoteConnect and SCADAPack 代码问题漏洞 — RemoteConnect and SCADAPack x70 Utilities | 7.8 | High | 2025-01-17 |
| CVE-2024-56515 | Matrix 代码问题漏洞 — matrix-media-repo | 6.8 | Medium | 2025-01-16 |
| CVE-2025-21364 | Microsoft Excel 代码问题漏洞 — Microsoft 365 Apps for Enterprise | 7.8 | High | 2025-01-14 |
| CVE-2025-0465 | AquilaCMS 安全漏洞 — AquilaCMS | 7.3 | High | 2025-01-14 |
| CVE-2024-13163 | Ivanti EPM 代码问题漏洞 — Endpoint Manager | 7.8 | High | 2025-01-14 |
| CVE-2025-22777 | WordPress plugin GiveWP 安全漏洞 — GiveWP | 9.8 | Critical | 2025-01-13 |
| CVE-2024-12877 | WordPress plugin GiveWP 代码问题漏洞 — GiveWP – Donation Plugin and Fundraising Platform | 9.8 | Critical | 2025-01-11 |
| CVE-2024-12627 | WordPress plugin Coupon X 代码问题漏洞 — Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce | 7.5 | High | 2025-01-11 |
| CVE-2024-13297 | Drupal 安全漏洞 — Eloqua | 9.8 | - | 2025-01-09 |
| CVE-2024-13296 | Drupal 安全漏洞 — Mailjet | 9.8 | - | 2025-01-09 |
| CVE-2024-13295 | Drupal 安全漏洞 — Node export | 9.8 | - | 2025-01-09 |
| CVE-2024-13288 | Drupal 安全漏洞 — Monster Menus | 9.8 | - | 2025-01-09 |
| CVE-2025-22510 | WordPress plugin WC Price History for Omnibus 代码问题漏洞 — WC Price History for Omnibus | 7.2 | High | 2025-01-09 |
| CVE-2024-54676 | Apache OpenMeetings 代码问题漏洞 — Apache OpenMeetings | 9.8 | - | 2025-01-08 |
| CVE-2024-49222 | WordPress plugin WPGuppy 代码问题漏洞 — WPGuppy | 9.8 | Critical | 2025-01-07 |
| CVE-2024-56283 | WordPress plugin Locatoraid Store Locator 代码问题漏洞 — Locatoraid Store Locator | 8.1 | High | 2025-01-07 |
| CVE-2024-56291 | WordPress plugin PlainInventory 代码问题漏洞 — PlainInventory | 8.1 | High | 2025-01-07 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 2188 条 CVE 漏洞。