CWE-502 可信数据的反序列化 类弱点 1687 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-7876 | Metasoft MetaCRM 代码问题漏洞 — MetaCRM | 6.3 | Medium | 2025-07-20 |
| CVE-2025-53770 | Microsoft SharePoint Server 安全漏洞 — Microsoft SharePoint Enterprise Server 2016 | 9.8 | Critical | 2025-07-20 |
| CVE-2025-7697 | WordPress plugin Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms 代码问题漏洞 — Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms | 9.8 | Critical | 2025-07-19 |
| CVE-2025-7696 | WordPress plugin Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms 代码问题漏洞 — Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms | 9.8 | Critical | 2025-07-19 |
| CVE-2025-7433 | Sophos Intercept X 安全漏洞 — Sophos Intercept X for Windows | 8.8 | High | 2025-07-17 |
| CVE-2025-24779 | WordPress plugin Yogi 代码问题漏洞 — Yogi | 8.8 | High | 2025-07-16 |
| CVE-2025-24777 | WordPress plugin Hillter 代码问题漏洞 — Hillter | 8.8 | High | 2025-07-16 |
| CVE-2025-28961 | WordPress plugin URL Shortener 代码问题漏洞 — URL Shortener | 9.8 | Critical | 2025-07-16 |
| CVE-2025-30949 | WordPress plugin Site Chat on Telegram 代码问题漏洞 — Site Chat on Telegram | 9.8 | Critical | 2025-07-16 |
| CVE-2025-30973 | WordPress plugin CoSchool LMS 代码问题漏洞 — CoSchool LMS | 9.8 | Critical | 2025-07-16 |
| CVE-2025-31422 | WordPress plugin Visual Art | Gallery WordPress Theme 代码问题漏洞 — Visual Art | Gallery WordPress Theme | 8.8 | High | 2025-07-16 |
| CVE-2025-53990 | WordPress plugin JetFormBuilder 代码问题漏洞 — JetFormBuilder | 7.2 | High | 2025-07-16 |
| CVE-2025-49841 | GPT-SoVITS-WebUI 代码问题漏洞 — GPT-SoVITS | 9.8AI | CriticalAI | 2025-07-15 |
| CVE-2025-49840 | GPT-SoVITS-WebUI 代码问题漏洞 — GPT-SoVITS | 9.8AI | CriticalAI | 2025-07-15 |
| CVE-2025-49839 | GPT-SoVITS-WebUI 代码问题漏洞 — GPT-SoVITS | 9.8AI | CriticalAI | 2025-07-15 |
| CVE-2025-49838 | GPT-SoVITS-WebUI 代码问题漏洞 — GPT-SoVITS | 9.8AI | CriticalAI | 2025-07-15 |
| CVE-2025-49837 | GPT-SoVITS-WebUI 代码问题漏洞 — GPT-SoVITS | 9.8AI | CriticalAI | 2025-07-15 |
| CVE-2025-7504 | WordPress plugin Friends 代码问题漏洞 — Friends | 7.5 | High | 2025-07-12 |
| CVE-2025-30025 | AXIS多款产品 安全漏洞 — AXIS Device Manager | 7.8AI | HighAI | 2025-07-11 |
| CVE-2025-30023 | AXIS多款产品 安全漏洞 — AXIS Camera Station Pro | 9.0 | Critical | 2025-07-11 |
| CVE-2025-6742 | WordPress plugin SureForms 代码问题漏洞 — SureForms – Drag and Drop Form Builder for WordPress | 7.5 | High | 2025-07-09 |
| CVE-2025-7216 | aidigu 安全漏洞 — Aidigu | 7.3 | High | 2025-07-09 |
| CVE-2025-49533 | Adobe Experience Manager 代码问题漏洞 — Adobe Experience Manager (MS) | 9.8 | Critical | 2025-07-08 |
| CVE-2025-27203 | Adobe Connect 代码问题漏洞 — Adobe Connect | 9.6 | Critical | 2025-07-08 |
| CVE-2025-47994 | Microsoft Office 代码问题漏洞 — Microsoft 365 Apps for Enterprise | 7.8 | High | 2025-07-08 |
| CVE-2025-42980 | SAP NetWeaver Enterprise Portal Federated Portal Network 代码问题漏洞 — SAP NetWeaver Enterprise Portal Federated Portal Network | 9.1 | Critical | 2025-07-08 |
| CVE-2025-42966 | SAP NetWeaver 代码问题漏洞 — SAP NetWeaver (XML Data Archiving Service) | 9.1 | Critical | 2025-07-08 |
| CVE-2025-42964 | SAP NetWeaver Enterprise Portal Administration 代码问题漏洞 — SAP NetWeaver Enterprise Portal Administration | 9.1 | Critical | 2025-07-08 |
| CVE-2025-42963 | SAP NetWeaver Application Server for Java 代码问题漏洞 — SAP NetWeaver Application Server for Java (Log Viewer ) | 9.1 | Critical | 2025-07-08 |
| CVE-2025-6811 | Mescius ActiveReports.NET 代码问题漏洞 — ActiveReports.NET | 9.8AI | CriticalAI | 2025-07-07 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 1687 条 CVE 漏洞。