CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,829 vulnerabilities with CWE-502
CVE-2024-30223
CRITICAL
Repute Infosystems ARMember <4.0.26 - Deserialization
CVSS 9.0
CVE-2024-30222
HIGH
Repute Infosystems ARMember <4.0.26 - Deserialization
CVSS 8.5
CVE-2024-1770
HIGH
Meta Tag Manager <3.0.2 - Code Injection
CVSS 8.8
CVE-2024-24842
HIGH
Knowledge Base for Documentation, FAQs with AI Assistance <= 11.30.2 - PHP Object Injection
CVSS 8.7
CVE-2024-24725
HIGH
Gibbon < 26.0.00 - Authenticated PHP Deserialization via columnOrder Parameter
CVSS 8.8
CVE-2024-2025
HIGH
BuddyPress WooCommerce My Account Integration - Code Injection
CVSS 8.8
CVE-2024-28861
CRITICAL
symfony1 1.1.0-1.5.18 - Remote Code Execution via sfNamespacedParameterHolder Deserialization
CVSS 9.8
CVE-2024-2054
CRITICAL
Artica-Proxy - Unauthenticated Remote Code Execution via PHP Deserialization
CVSS 9.8
CVE-2024-29032
MEDIUM
Qiskit IBM Runtime 0.1.0-0.21.1 - Remote Code Execution via RuntimeDecoder JSON Deserialization
CVSS 5.3
CVE-2024-1856
HIGH
Progress Telerik Reporting < 18.0.24.130 - Remote Code Execution via Insecure Deserialization
CVSS 8.5
CVE-2024-1801
HIGH
Progress Telerik Reporting < 18.0.24.130 - Local Code Execution via Insecure Deserialization
CVSS 7.7
CVE-2024-1800
CRITICAL
Progress Telerik Report Server < 10.0.24.130 - Remote Code Execution via Insecure Deserialization
CVSS 9.9
CVE-2024-2721
HIGH
Social Media Share Buttons By Sygnoos < 2.1.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.2
CVE-2024-29136
HIGH
Themefic Tourfic <= 2.11.17 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.5
CVE-2024-2229
HIGH
EcoStruxure Power Design - Ecodial - Remote Code Execution via Malicious Project File Deserialization
CVSS 7.8
CVE-2024-1685
HIGH
Social Media Share Buttons < 2.1.0 - Authenticated PHP Object Injection via attachmentUrl Parameter
CVSS 8.8
CVE-2024-28859
MEDIUM
symfony1 1.3.0-1.5.17 - Remote Code Execution via Swift Mailer Gadget Chain
CVSS 5.0
CVE-2024-2006
HIGH
Post Grid, Slider & Carousel Ultimate < 1.6.8 - Authenticated PHP Object Injection via outpost_shortcode_metabox_markup
CVSS 8.8
CVE-2024-1951
HIGH
Logo Showcase Ultimate - Code Injection
CVSS 7.5
CVE-2024-1950
HIGH
Product Carousel Slider & Grid Ultimate - Code Injection
CVSS 7.5
CVE-2024-1772
HIGH
Play.ht <= 3.6.4 - Authenticated PHP Object Injection via play_podcast_data
CVSS 8.8
CVE-2024-0047
MEDIUM
Android - Local Denial of Service via Incorrect Device Policy Serialization Tag
CVSS 5.5
CVE-2024-1773
HIGH
PDF Invoices and Packing Slips For WooCommerce <= 1.3.7 - Authenticated PHP Object Injection via order_id Parameter
CVSS 8.8
CVE-2024-28213
CRITICAL
nGrinder < 3.5.9 - Unauthenticated Remote Code Execution via Java Deserialization
CVSS 9.8
CVE-2024-28212
CRITICAL
nGrinder < 3.5.9 - Remote Code Execution via Unsafe SnakeYAML Deserialization
CVSS 9.8
Details
Vulnerabilities
2,829
Exploit Likelihood
Medium