CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,829 vulnerabilities with CWE-502
CVE-2024-28211 CRITICAL
nGrinder < 3.5.9 - Remote Code Execution via Malicious JMX/RMI Server Connection
CVSS 9.8
CVE-2024-26580 CRITICAL
Apache InLong 1.8.0-1.10.0 - Arbitrary File Read via Deserialization
CVSS 9.1
CVE-2024-1731 HIGH
Auto Refresh Single Page < 1.1 - Authenticated PHP Object Injection via arsp_options Post Meta
CVSS 8.8
CVE-2024-0825 HIGH
Vimeography < 2.3.3 - Authenticated PHP Object Injection via duplicate_gallery Function
CVSS 8.8
CVE-2024-24302 CRITICAL
Product Designer < 1.178.36 - Remote Code Execution via postProcess() Method
CVSS 9.8
CVE-2024-0692 HIGH
SolarWinds Security Event Manager - RCE
CVSS 8.8
CVE-2024-1859 HIGH
Slider Responsive Slideshow < 1.3.8 - Authenticated PHP Object Injection via awl_slider_responsive_shortcode
CVSS 8.8
CVE-2024-22871 HIGH
Clojure 1.2.0-1.11.2 - Denial of Service via clojure.core$partial$fn__5920
CVSS 7.5
CVE-2024-23328 CRITICAL
Dataease < 1.18.15 - Deserialization of Untrusted Data in MySQL Datasource
CVSS 9.1
CVE-2024-23052 CRITICAL
WuKongOpenSource WukongCRM <9.0.1 - RCE
CVSS 9.8
CVE-2024-1750 MEDIUM
temmokumvc < 2.3 - Deserialization of Untrusted Data in Image Download Handler
CVSS 5.6
CVE-2024-1748 MEDIUM
AutoPrognosis 0.1.21 - Deserialization of Untrusted Data in Release Note Handler
CVSS 5.0
CVE-2024-25117 MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-23114 CRITICAL
Apache Camel 3.0.0-3.21.3, 3.22.0, 4.0.0-4.0.3, 4.1.0-4.3.0 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-22369 HIGH
Apache Camel <4.4.0 - Deserialization
CVSS 7.8
CVE-2024-1651 CRITICAL
Torrentpier 2.4.1 - Remote Code Execution via Insecure Deserialization
CVSS 10.0
CVE-2024-20953 HIGH KEV
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Export Component Deserialization
CVSS 8.8
CVE-2024-23478 HIGH
SolarWinds Access Rights Manager < 2023.2.3 - Authenticated Remote Code Execution via Deserialization
CVSS 8.0
CVE-2024-23759 CRITICAL
Gambio <= 4.9.2.0 - Remote Code Execution via Parcelshopfinder AddAddressBookEntry Search Parameter
CVSS 9.8
CVE-2024-23512 HIGH
wpxpo ProductX < 3.1.4 - PHP Object Injection via Untrusted Data Deserialization
CVSS 8.7
CVE-2024-24926 HIGH
UnitedThemes Brooklyn <4.9.7.6 - Deserialization
CVSS 7.5
CVE-2024-24797 CRITICAL
ERE Recently Viewed - Essential Real Estate Add-On <= 1.3 - Unauthenticated PHP Object Injection
CVSS 9.8
CVE-2024-24796 HIGH
Mage-people Event Manager And Tickets Selling For Woocommerce < 4.1.2 - Insecure Deserialization
CVSS 8.2
CVE-2024-23513 HIGH
PropertyHive < 2.0.5 - Deserialization of Untrusted Data
CVSS 8.7
CVE-2024-25100 CRITICAL
WP Swings Coupon Referral Program <1.8.4 - Code Injection
CVSS 10.0
Details
Vulnerabilities 2,829
Exploit Likelihood Medium