Insecure Deserialization
Object reconstruction from attacker-influenced data, including allow-list bypasses.
Published work on this topic
| 2026-09-08 | CVE-2026-16723 | CVE-2026-16723 Exploit: fastjson RCE | PoC | |
| 2026-09-07 | CVE-2025-55182 | CVE-2025-55182: React2Shell Pre-Auth RCE | PoC | |
| 2026-08-15 | CVE-2026-34486 | CVE-2026-34486: Tomcat Tribes RCE | PoC | |
| 2026-08-11 | CVE-2025-24813 | CVE-2025-24813: Apache Tomcat Partial PUT RCE | PoC |
Other topics
remote code execution31authentication bypass18php11wordpress10authorization bypass9java9privilege escalation7sql injection7heap overflow6code injection5denial of service5path traversal5qemu5apache tomcat4go4information disclosure4node.js4cross-site scripting4buffer overflow3javascript3joomla3python3stored xss3
