CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,829 vulnerabilities with CWE-502
CVE-2024-28211
CRITICAL
nGrinder < 3.5.9 - Remote Code Execution via Malicious JMX/RMI Server Connection
CVSS 9.8
CVE-2024-26580
CRITICAL
Apache InLong 1.8.0-1.10.0 - Arbitrary File Read via Deserialization
CVSS 9.1
CVE-2024-1731
HIGH
Auto Refresh Single Page < 1.1 - Authenticated PHP Object Injection via arsp_options Post Meta
CVSS 8.8
CVE-2024-0825
HIGH
Vimeography < 2.3.3 - Authenticated PHP Object Injection via duplicate_gallery Function
CVSS 8.8
CVE-2024-24302
CRITICAL
Product Designer < 1.178.36 - Remote Code Execution via postProcess() Method
CVSS 9.8
CVE-2024-0692
HIGH
SolarWinds Security Event Manager - RCE
CVSS 8.8
CVE-2024-1859
HIGH
Slider Responsive Slideshow < 1.3.8 - Authenticated PHP Object Injection via awl_slider_responsive_shortcode
CVSS 8.8
CVE-2024-22871
HIGH
Clojure 1.2.0-1.11.2 - Denial of Service via clojure.core$partial$fn__5920
CVSS 7.5
CVE-2024-23328
CRITICAL
Dataease < 1.18.15 - Deserialization of Untrusted Data in MySQL Datasource
CVSS 9.1
CVE-2024-23052
CRITICAL
WuKongOpenSource WukongCRM <9.0.1 - RCE
CVSS 9.8
CVE-2024-1750
MEDIUM
temmokumvc < 2.3 - Deserialization of Untrusted Data in Image Download Handler
CVSS 5.6
CVE-2024-1748
MEDIUM
AutoPrognosis 0.1.21 - Deserialization of Untrusted Data in Release Note Handler
CVSS 5.0
CVE-2024-25117
MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-23114
CRITICAL
Apache Camel 3.0.0-3.21.3, 3.22.0, 4.0.0-4.0.3, 4.1.0-4.3.0 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-22369
HIGH
Apache Camel <4.4.0 - Deserialization
CVSS 7.8
CVE-2024-1651
CRITICAL
Torrentpier 2.4.1 - Remote Code Execution via Insecure Deserialization
CVSS 10.0
CVE-2024-20953
HIGH
KEV
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Export Component Deserialization
CVSS 8.8
CVE-2024-23478
HIGH
SolarWinds Access Rights Manager < 2023.2.3 - Authenticated Remote Code Execution via Deserialization
CVSS 8.0
CVE-2024-23759
CRITICAL
Gambio <= 4.9.2.0 - Remote Code Execution via Parcelshopfinder AddAddressBookEntry Search Parameter
CVSS 9.8
CVE-2024-23512
HIGH
wpxpo ProductX < 3.1.4 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.7
CVE-2024-24926
HIGH
UnitedThemes Brooklyn <4.9.7.6 - Deserialization
CVSS 7.5
CVE-2024-24797
CRITICAL
ERE Recently Viewed - Essential Real Estate Add-On <= 1.3 - Unauthenticated PHP Object Injection
CVSS 9.8
CVE-2024-24796
HIGH
Mage-people Event Manager And Tickets Selling For Woocommerce < 4.1.2 - Insecure Deserialization
CVSS 8.2
CVE-2024-23513
HIGH
PropertyHive < 2.0.5 - Deserialization of Untrusted Data
CVSS 8.7
CVE-2024-25100
CRITICAL
WP Swings Coupon Referral Program <1.8.4 - Code Injection
CVSS 10.0
Details
Vulnerabilities
2,829
Exploit Likelihood
Medium