CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,829 vulnerabilities with CWE-502
CVE-2024-40624
CRITICAL
TorrentPier < 2.4.4 - Remote Code Execution via Unsafe Cookie Deserialization
CVSS 9.8
CVE-2024-6645
MEDIUM
WuKongOpenSource Wukong_nocode - Deserialization
CVSS 6.3
CVE-2024-6644
MEDIUM
zmops ArgusDBM <0.1.0 - Deserialization
CVSS 6.3
CVE-2024-31317
HIGH
Android - Local Privilege Escalation via Unsafe Deserialization in ZygoteProcess.java
CVSS 7.8
CVE-2024-38094
HIGH
KEV
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-38024
HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-38023
HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-37502
MEDIUM
WooCommerce Social Login <= 2.6.3 - Deserialization of Untrusted Data
CVSS 5.4
CVE-2024-5488
CRITICAL
SEOPress < 7.9 - Unauthenticated Deserialization of Untrusted Data via REST API
CVSS 9.8
CVE-2024-6525
LOW
D-Link DAR-7000 <20230922 - Deserialization
CVSS 2.7
CVE-2024-6441
MEDIUM
ORIPA < 1.80 - Deserialization of Untrusted Data in LoaderXML
CVSS 6.3
CVE-2024-36984
HIGH
Splunk 9.0.0-9.0.10 - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2024-29040
MEDIUM
tpm2-tss < 4.1.0 - Deserialization of Untrusted Data in Fapi_VerifyQuote
CVSS 4.3
CVE-2024-39705
CRITICAL
NLTK < 3.9 - Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2024-5016
HIGH
WhatsUp Gold < 23.1.0 - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-24551
HIGH
Bludit < 3.15.0 - Authenticated Remote Code Execution via Image API File Upload
CVSS 8.8
CVE-2024-24550
HIGH
Bludit 3.14.0-3.15.0 - Arbitrary File Upload to Code Execution
CVSS 8.1
CVE-2024-39334
MEDIUM
MENDELSON AS4 <2024 B376 - Code Injection
CVSS 6.5
CVE-2024-32030
HIGH
Kafka UI < 0.7.2 - Remote Code Execution via JMX Deserialization
CVSS 8.1
CVE-2024-35780
HIGH
Live Composer <1.5.42 - Deserialization
CVSS 8.5
CVE-2024-5724
HIGH
Photo Video Gallery Master <= 1.5.3 - Authenticated PHP Object Injection via PVGM_all_photos_details Parameter
CVSS 8.8
CVE-2024-5649
MEDIUM
Universal Slider <1.6.5 - Code Injection
CVSS 5.4
CVE-2024-5871
CRITICAL
WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object Injection via woo_slg_verify Parameter
CVSS 9.8
CVE-2024-5671
CRITICAL
Trellix IPS Manager < 11.1.x - Unauthenticated RCE via Insecure Deserialization
CVSS 9.8
CVE-2024-4371
CRITICAL
CoDesigner < 4.5 - Unauthenticated PHP Object Injection via recently_viewed_products Cookie
CVSS 9.0
Details
Vulnerabilities
2,829
Exploit Likelihood
Medium