CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,829 vulnerabilities with CWE-502
CVE-2024-43354 CRITICAL
myCred <= 2.7.2 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-43252 CRITICAL
Crew HRM <= 1.1.1 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.0
CVE-2024-43242 CRITICAL
Ultimate Membership Pro <12.6 - Code Injection
CVSS 9.0
CVE-2024-37099 CRITICAL
GiveWP < 3.14.1 - Unauthenticated PHP Object Injection via Deserialization
CVSS 10.0
CVE-2024-28986 CRITICAL KEV
SolarWinds Web Help Desk < 12.8.3 - Insecure Deserialization
CVSS 9.8
CVE-2024-43141 CRITICAL
Roland Barker xnau webdesign Participants Database <2.5.9.2 - Code ...
CVSS 9.8
CVE-2024-7561 HIGH
The Next < 1.1.0 - Authenticated PHP Object Injection via wpeden_post_meta Deserialization
CVSS 8.8
CVE-2024-7560 HIGH
News Flash <= 1.1.0 - Authenticated PHP Object Injection via newsflash_post_meta Deserialization
CVSS 7.2
CVE-2024-7486 HIGH
MultiPurpose <= 1.2.0 - Authenticated PHP Object Injection via wpeden_post_meta Deserialization
CVSS 8.8
CVE-2024-36131 HIGH
Ivanti Endpoint Manager Mobile < 12.1.0.1 - Authenticated Remote Code Execution via Insecure Deserialization
CVSS 8.8
CVE-2024-39636 HIGH
CodeSolz Better Find and Replace <1.6.1 - Deserialization
CVSS 8.3
CVE-2024-39630 MEDIUM
MotoPress Timetable <2.4.13 - Object Injection
CVSS 5.5
CVE-2024-6152 HIGH
Flipbox Builder <1.5 - Code Injection
CVSS 8.8
CVE-2024-39673 MEDIUM
Huawei EMUI and HarmonyOS - Deserialization of Untrusted Data in iAware Module
CVSS 6.8
CVE-2024-7067 MEDIUM
shuttur/ecommerce-laravel-bootstrap < 2024-07-03 - Deserialization of Untrusted Data in getCartProductsIds
CVSS 6.3
CVE-2024-6327 CRITICAL
Telerik Report Server <2024 Q2 - Code Injection
CVSS 9.9
CVE-2024-6794 CRITICAL
NI VeriStand <2024 Q2 - Deserialization
CVSS 9.8
CVE-2024-6793 CRITICAL
NI VeriStand < 2024 Q2 - Remote Code Execution via Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-6675 HIGH
NI VeriStand <2024 Q2 - Code Injection
CVSS 7.8
CVE-2024-38759 MEDIUM
WP MEDIA SAS Search & Replace < 3.2.2 - Deserialization of Untrusted Data
CVSS 5.4
CVE-2024-6960 HIGH
H2O Core - Remote Code Execution via Iced Model Deserialization
CVSS 7.5
CVE-2024-6944 MEDIUM
crmeb < 5.4.0 - Remote Code Execution via Untrusted Data Deserialization in PublicController.php
CVSS 6.3
CVE-2024-6943 MEDIUM
crmeb < 5.4.0 - Deserialization of Untrusted Data via CopyTaobaoServices downloadImage Function
CVSS 6.3
CVE-2024-5726 HIGH
Timeline Event History <3.1 - Code Injection
CVSS 8.8
CVE-2024-28074 CRITICAL
SolarWinds Access Rights Manager < 2023.2.4 - Deserialization of Untrusted Data
CVSS 9.6
Details
Vulnerabilities 2,829
Exploit Likelihood Medium