CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,829 vulnerabilities with CWE-502
CVE-2024-43354
CRITICAL
myCred <= 2.7.2 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-43252
CRITICAL
Crew HRM <= 1.1.1 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.0
CVE-2024-43242
CRITICAL
Ultimate Membership Pro <12.6 - Code Injection
CVSS 9.0
CVE-2024-37099
CRITICAL
GiveWP < 3.14.1 - Unauthenticated PHP Object Injection via Deserialization
CVSS 10.0
CVE-2024-28986
CRITICAL
KEV
SolarWinds Web Help Desk < 12.8.3 - Insecure Deserialization
CVSS 9.8
CVE-2024-43141
CRITICAL
Roland Barker xnau webdesign Participants Database <2.5.9.2 - Code ...
CVSS 9.8
CVE-2024-7561
HIGH
The Next < 1.1.0 - Authenticated PHP Object Injection via wpeden_post_meta Deserialization
CVSS 8.8
CVE-2024-7560
HIGH
News Flash <= 1.1.0 - Authenticated PHP Object Injection via newsflash_post_meta Deserialization
CVSS 7.2
CVE-2024-7486
HIGH
MultiPurpose <= 1.2.0 - Authenticated PHP Object Injection via wpeden_post_meta Deserialization
CVSS 8.8
CVE-2024-36131
HIGH
Ivanti Endpoint Manager Mobile < 12.1.0.1 - Authenticated Remote Code Execution via Insecure Deserialization
CVSS 8.8
CVE-2024-39636
HIGH
CodeSolz Better Find and Replace <1.6.1 - Deserialization
CVSS 8.3
CVE-2024-39630
MEDIUM
MotoPress Timetable <2.4.13 - Object Injection
CVSS 5.5
CVE-2024-6152
HIGH
Flipbox Builder <1.5 - Code Injection
CVSS 8.8
CVE-2024-39673
MEDIUM
Huawei EMUI and HarmonyOS - Deserialization of Untrusted Data in iAware Module
CVSS 6.8
CVE-2024-7067
MEDIUM
shuttur/ecommerce-laravel-bootstrap < 2024-07-03 - Deserialization of Untrusted Data in getCartProductsIds
CVSS 6.3
CVE-2024-6327
CRITICAL
Telerik Report Server <2024 Q2 - Code Injection
CVSS 9.9
CVE-2024-6794
CRITICAL
NI VeriStand <2024 Q2 - Deserialization
CVSS 9.8
CVE-2024-6793
CRITICAL
NI VeriStand < 2024 Q2 - Remote Code Execution via Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-6675
HIGH
NI VeriStand <2024 Q2 - Code Injection
CVSS 7.8
CVE-2024-38759
MEDIUM
WP MEDIA SAS Search & Replace < 3.2.2 - Deserialization of Untrusted Data
CVSS 5.4
CVE-2024-6960
HIGH
H2O Core - Remote Code Execution via Iced Model Deserialization
CVSS 7.5
CVE-2024-6944
MEDIUM
crmeb < 5.4.0 - Remote Code Execution via Untrusted Data Deserialization in PublicController.php
CVSS 6.3
CVE-2024-6943
MEDIUM
crmeb < 5.4.0 - Deserialization of Untrusted Data via CopyTaobaoServices downloadImage Function
CVSS 6.3
CVE-2024-5726
HIGH
Timeline Event History <3.1 - Code Injection
CVSS 8.8
CVE-2024-28074
CRITICAL
SolarWinds Access Rights Manager < 2023.2.4 - Deserialization of Untrusted Data
CVSS 9.6
Details
Vulnerabilities
2,829
Exploit Likelihood
Medium