CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,829 vulnerabilities with CWE-502
CVE-2023-35814 LOW
DevExpress < 23.1.3 - Deserialization of Untrusted Data in XtraReport
CVSS 3.5
CVE-2023-27531 MEDIUM
Kredis < 1.3.0.1 - Deserialization of Untrusted Data via JSON Deserialization
CVSS 5.3
CVE-2023-51642 MEDIUM
Allegra <= 7.5.1 loadFieldMatch - Deserialization Code Execution
CVSS 6.3
CVE-2023-51641 MEDIUM
Allegra < 7.5.1 - Authenticated Remote Code Execution via renderFieldMatch Deserialization
CVSS 6.3
CVE-2023-32736 HIGH
SIMATIC S7-PLCSIM V16 and V17 - Remote Code Execution via Deserialization of Untrusted Data
CVSS 7.3
CVE-2023-25581 CRITICAL
pac4j-core < 4.0.0 - Remote Code Execution via Java Deserialization with {#sb64} Prefix
CVE-2023-37227 CRITICAL
Loftware Spectrum < 4.6 HF13 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2023-49566 HIGH
Apache Linkis <=1.5.0 - Authenticated JNDI Injection via DB2 DataSource Parameters
CVSS 8.8
CVE-2023-46801 HIGH
Apache Linkis <=1.5.0 - Authenticated RCE
CVSS 8.8
CVE-2023-32737 MEDIUM
SIMATIC STEP 7 Safety <V18 Update 2 - Code Injection
CVSS 6.3
CVE-2023-32735 MEDIUM
SIMATIC STEP 7 Safety <V16.7-V18.2, SIMATIC STEP 7 <V16.7-V18.2, SI...
CVSS 6.5
CVE-2023-38264 MEDIUM
IBM SDK Java 7.1.0.0-7.1.5.21 & 8.0.0.0-8.0.8.21 - DoS via ORB Deserialization Filter Bypass
CVSS 5.9
CVE-2023-51576 CRITICAL
Voltronic Power ViewPower - Deserialization
CVSS 9.8
CVE-2023-50223 HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Remote Code Execution via Deserialization
CVSS 8.8
CVE-2023-50222 HIGH
Inductive Automation Ignition 8.1.0-8.1.34 - Remote Code Execution via ResponseParser Deserialization
CVSS 8.8
CVE-2023-50221 HIGH
Inductive Automation Ignition 8.1.0-8.1.34 - Remote Code Execution via ResponseParser Deserialization
CVSS 8.8
CVE-2023-50220 HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Authenticated Remote Code Execution via Base64Element Deserialization
CVSS 8.8
CVE-2023-50219 HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Authenticated Remote Code Execution via RunQuery Deserialization
CVSS 8.8
CVE-2023-50218 HIGH
Inductive Automation Ignition 8.1.0-8.1.35 - Authenticated Remote Code Execution via ModuleInvoke Deserialization
CVSS 8.8
CVE-2023-39476 CRITICAL
Inductive Automation Ignition 8.1.0-8.1.34 - RCE via Java Deserialization
CVSS 9.8
CVE-2023-39475 CRITICAL
Inductive Automation Ignition 8.1.0-8.1.34 - RCE via ParameterVersionJavaSerializationCodec Deserialization
CVSS 9.8
CVE-2023-39473 HIGH
Inductive Automation Ignition 8.1.0-8.1.34 - Remote Code Execution via Deserialization
CVSS 8.8
CVE-2023-7064 HIGH
Shortcodes and extra features for Phlox theme < 2.17.5 - Authenticated PHP Object Injection via 'id' Parameter
CVSS 7.5
CVE-2023-51570 CRITICAL
Voltronic Power ViewPower Pro - Deserialization
CVSS 9.8
CVE-2023-23649 HIGH
MainWP MainWP Links Manager Extension <2.1 - Deserialization
CVSS 8.1
Details
Vulnerabilities 2,829
Exploit Likelihood Medium