Skip to content
Threat Feed

Tag

Insecure-Deserialization

5 briefs RSS
high advisory

Graphite graph database engine Insecure Deserialization Vulnerability

Graphite versions before 0.2 are vulnerable to insecure deserialization due to the use of Python's `pickle` module for database storage, allowing attackers to craft malicious database files that execute arbitrary code when loaded.

graphitedb insecure-deserialization code-execution
1r 1t
critical advisory

Perfex CRM Unauthenticated Remote Code Execution via Insecure Deserialization

Perfex CRM is vulnerable to unauthenticated remote code execution (RCE) due to an autologin cookie being fed into unserialize().

Perfex CRM perfex-crm rce insecure-deserialization php
2r 1t 2i
high advisory

Grav File Cache Insecure Deserialization Vulnerability

Grav versions 1.7.44 through 1.7.49.5 are vulnerable to insecure deserialization in the File Cache component, where the `unserialize` function with `allowed_classes => true` can lead to arbitrary code execution if an attacker tampers with cache files.

grav insecure-deserialization code-execution web-application
2r 2t
high advisory

MONAI Library Vulnerable to Arbitrary Code Execution via Pickle Deserialization

The MONAI library is vulnerable to arbitrary code execution due to insecure deserialization of pickle files via the `algo_from_pickle` function, allowing attackers to execute arbitrary code by providing a malicious pickle file.

MONAI pickle rce insecure-deserialization python
2r 1t
high advisory

Gigabyte Control Center Insecure Deserialization Privilege Escalation (CVE-2026-4416)

A local, authenticated attacker can exploit an insecure deserialization vulnerability in the Gigabyte Control Center's Performance Library component by sending a malicious serialized payload to the EasyTune Engine service, leading to privilege escalation.

Control Center insecure-deserialization privilege-escalation windows
2r 1t