CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,829 vulnerabilities with CWE-502
CVE-2023-35814
LOW
DevExpress < 23.1.3 - Deserialization of Untrusted Data in XtraReport
CVSS 3.5
CVE-2023-27531
MEDIUM
Kredis < 1.3.0.1 - Deserialization of Untrusted Data via JSON Deserialization
CVSS 5.3
CVE-2023-51642
MEDIUM
Allegra <= 7.5.1 loadFieldMatch - Deserialization Code Execution
CVSS 6.3
CVE-2023-51641
MEDIUM
Allegra < 7.5.1 - Authenticated Remote Code Execution via renderFieldMatch Deserialization
CVSS 6.3
CVE-2023-32736
HIGH
SIMATIC S7-PLCSIM V16 and V17 - Remote Code Execution via Deserialization of Untrusted Data
CVSS 7.3
CVE-2023-25581
CRITICAL
pac4j-core < 4.0.0 - Remote Code Execution via Java Deserialization with {#sb64} Prefix
CVE-2023-37227
CRITICAL
Loftware Spectrum < 4.6 HF13 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2023-49566
HIGH
Apache Linkis <=1.5.0 - Authenticated JNDI Injection via DB2 DataSource Parameters
CVSS 8.8
CVE-2023-46801
HIGH
Apache Linkis <=1.5.0 - Authenticated RCE
CVSS 8.8
CVE-2023-32737
MEDIUM
SIMATIC STEP 7 Safety <V18 Update 2 - Code Injection
CVSS 6.3
CVE-2023-32735
MEDIUM
SIMATIC STEP 7 Safety <V16.7-V18.2, SIMATIC STEP 7 <V16.7-V18.2, SI...
CVSS 6.5
CVE-2023-38264
MEDIUM
IBM SDK Java 7.1.0.0-7.1.5.21 & 8.0.0.0-8.0.8.21 - DoS via ORB Deserialization Filter Bypass
CVSS 5.9
CVE-2023-51576
CRITICAL
Voltronic Power ViewPower - Deserialization
CVSS 9.8
CVE-2023-50223
HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Remote Code Execution via Deserialization
CVSS 8.8
CVE-2023-50222
HIGH
Inductive Automation Ignition 8.1.0-8.1.34 - Remote Code Execution via ResponseParser Deserialization
CVSS 8.8
CVE-2023-50221
HIGH
Inductive Automation Ignition 8.1.0-8.1.34 - Remote Code Execution via ResponseParser Deserialization
CVSS 8.8
CVE-2023-50220
HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Authenticated Remote Code Execution via Base64Element Deserialization
CVSS 8.8
CVE-2023-50219
HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Authenticated Remote Code Execution via RunQuery Deserialization
CVSS 8.8
CVE-2023-50218
HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Authenticated Remote Code Execution via ModuleInvoke Deserialization
CVSS 8.8
CVE-2023-39476
CRITICAL
Inductive Automation Ignition 8.1.0-8.1.34 - RCE via Java Deserialization
CVSS 9.8
CVE-2023-39475
CRITICAL
Inductive Automation Ignition 8.1.0-8.1.34 - RCE via ParameterVersionJavaSerializationCodec Deserialization
CVSS 9.8
CVE-2023-39473
HIGH
Inductive Automation Ignition 8.1.0-8.1.34 - Remote Code Execution via Deserialization
CVSS 8.8
CVE-2023-7064
HIGH
Shortcodes and extra features for Phlox theme < 2.17.5 - Authenticated PHP Object Injection via 'id' Parameter
CVSS 7.5
CVE-2023-51570
CRITICAL
Voltronic Power ViewPower Pro - Deserialization
CVSS 9.8
CVE-2023-23649
HIGH
MainWP MainWP Links Manager Extension <2.1 - Deserialization
CVSS 8.1
Details
Vulnerabilities
2,829
Exploit Likelihood
Medium