CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,826 vulnerabilities with CWE-502
CVE-2024-45853
HIGH
MindsDB >= 23.10.2.0 - Remote Code Execution via Malicious Inhouse Model Deserialization
CVSS 7.1
CVE-2024-45852
HIGH
MindsDB >= 23.3.2.0 - Remote Code Execution via Untrusted Model Deserialization
CVSS 8.8
CVE-2024-29847
CRITICAL
Ivanti EPM <2022 SU6-2024 September - Code Injection
CVSS 9.8
CVE-2024-43466
MEDIUM
Microsoft SharePoint Server - Denial of Service via Deserialization of Untrusted Data
CVSS 6.5
CVE-2024-43464
HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-38018
HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2024-44902
CRITICAL
Thinkphp 6.1.3-8.0.4 - Code Injection
CVSS 9.8
CVE-2024-37288
CRITICAL
Kibana - Remote Code Execution via YAML Deserialization in AI Tools Amazon Bedrock Connector
CVSS 9.9
CVE-2024-40711
CRITICAL
KEV
Veeam Backup & Replication 12.0.0.1420 through 12.2.0.334 - Deserialization RCE
CVSS 9.8
CVE-2024-45758
CRITICAL
H2O < 3.46.0.4 - Unauthenticated Remote Code Execution via JDBC Connection URL Injection
CVSS 9.1
CVE-2024-7435
HIGH
Attire < 2.0.7 - Authenticated PHP Object Injection via Untrusted Input Deserialization
CVSS 8.8
CVE-2024-8016
CRITICAL
The Events Calendar Pro <7.0.2 - Code Injection
CVSS 9.1
CVE-2024-2694
HIGH
Betheme Theme <27.5.6 - Code Injection
CVSS 8.8
CVE-2024-8255
CRITICAL
Delta Electronics DTN Soft <2.0.1 - Code Injection
CVSS 9.8
CVE-2024-43931
CRITICAL
eyecix JobSearch < 2.5.3 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.8
CVE-2024-8030
CRITICAL
Ultimate Store Kit Elementor Addons <2.0.3 - Code Injection
CVSS 9.8
CVE-2024-7351
HIGH
Simple Job Board <= 2.12.3 - Authenticated PHP Object Injection via Job Application Edit
CVSS 7.2
CVE-2024-5335
CRITICAL
Ultimate Store Kit Elementor Addons <1.6.4 - Code Injection
CVSS 9.8
CVE-2024-42363
HIGH
Zendesk Samson <3385 Kubernetes Role - YAML Deserialization Code Execution
CVSS 8.8
CVE-2024-42362
HIGH
Hertzbeat < 1.6.0 - Authenticated Remote Code Execution via Unsafe Deserialization in Monitor Import
CVSS 8.8
CVE-2024-8003
LOW
Go-Tribe gotribe-admin <1.0 - Deserialization
CVSS 3.5
CVE-2024-5932
CRITICAL
GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection via give_title
CVSS 10.0
CVE-2024-43354
CRITICAL
myCred <= 2.7.2 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-43252
CRITICAL
Crew HRM <= 1.1.1 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.0
CVE-2024-43242
CRITICAL
Ultimate Membership Pro <12.6 - Code Injection
CVSS 9.0
Details
Vulnerabilities
2,826
Exploit Likelihood
Medium