CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,829 vulnerabilities with CWE-502
CVE-2024-40624 CRITICAL
TorrentPier < 2.4.4 - Remote Code Execution via Unsafe Cookie Deserialization
CVSS 9.8
CVE-2024-6645 MEDIUM
WuKongOpenSource Wukong_nocode - Deserialization
CVSS 6.3
CVE-2024-6644 MEDIUM
zmops ArgusDBM <0.1.0 - Deserialization
CVSS 6.3
CVE-2024-31317 HIGH
Android - Local Privilege Escalation via Unsafe Deserialization in ZygoteProcess.java
CVSS 7.8
CVE-2024-38094 HIGH KEV
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-38024 HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-38023 HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-37502 MEDIUM
WooCommerce Social Login <= 2.6.3 - Deserialization of Untrusted Data
CVSS 5.4
CVE-2024-5488 CRITICAL
SEOPress < 7.9 - Unauthenticated Deserialization of Untrusted Data via REST API
CVSS 9.8
CVE-2024-6525 LOW
D-Link DAR-7000 <20230922 - Deserialization
CVSS 2.7
CVE-2024-6441 MEDIUM
ORIPA < 1.80 - Deserialization of Untrusted Data in LoaderXML
CVSS 6.3
CVE-2024-36984 HIGH
Splunk 9.0.0-9.0.10 - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2024-29040 MEDIUM
tpm2-tss < 4.1.0 - Deserialization of Untrusted Data in Fapi_VerifyQuote
CVSS 4.3
CVE-2024-39705 CRITICAL
NLTK < 3.9 - Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2024-5016 HIGH
WhatsUp Gold < 23.1.0 - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2024-24551 HIGH
Bludit < 3.15.0 - Authenticated Remote Code Execution via Image API File Upload
CVSS 8.8
CVE-2024-24550 HIGH
Bludit 3.14.0-3.15.0 - Arbitrary File Upload to Code Execution
CVSS 8.1
CVE-2024-39334 MEDIUM
MENDELSON AS4 <2024 B376 - Code Injection
CVSS 6.5
CVE-2024-32030 HIGH
Kafka UI < 0.7.2 - Remote Code Execution via JMX Deserialization
CVSS 8.1
CVE-2024-35780 HIGH
Live Composer <1.5.42 - Deserialization
CVSS 8.5
CVE-2024-5724 HIGH
Photo Video Gallery Master <= 1.5.3 - Authenticated PHP Object Injection via PVGM_all_photos_details Parameter
CVSS 8.8
CVE-2024-5649 MEDIUM
Universal Slider <1.6.5 - Code Injection
CVSS 5.4
CVE-2024-5871 CRITICAL
WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object Injection via woo_slg_verify Parameter
CVSS 9.8
CVE-2024-5671 CRITICAL
Trellix IPS Manager < 11.1.x - Unauthenticated RCE via Insecure Deserialization
CVSS 9.8
CVE-2024-4371 CRITICAL
CoDesigner < 4.5 - Unauthenticated PHP Object Injection via recently_viewed_products Cookie
CVSS 9.0
Details
Vulnerabilities 2,829
Exploit Likelihood Medium