CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,829 vulnerabilities with CWE-502
CVE-2023-27459 HIGH
WPEverest User Registration < 2.3.2.1 - Authenticated PHP Object Injection
CVSS 7.4
CVE-2023-51518 CRITICAL
Apache James <3.7.5, 3.8.0 - Privilege Escalation
CVSS 9.8
CVE-2023-51389 CRITICAL
Hertzbeat < 1.4.1 - Deserialization of Untrusted Data via SnakeYAML Parser
CVSS 9.8
CVE-2023-52357 HIGH
Huawei EMUI and HarmonyOS - Denial of Service via Serialization/Deserialization Mismatch
CVSS 7.5
CVE-2023-40057 CRITICAL
SolarWinds Access Rights Manager < 2023.2.2 - Authenticated Remote Code Execution via Deserialization
CVSS 9.0
CVE-2023-26592 LOW
Intel(R) Thunderbolt(TM) DCH <88 - DoS
CVSS 3.8
CVE-2023-46615 MEDIUM
KD Coming Soon < 1.7 - PHP Object Injection via Untrusted Data Deserialization
CVSS 5.4
CVE-2023-6933 HIGH
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection via Untrusted Input Deserialization
CVSS 8.8
CVE-2023-50943 HIGH
Apache Airflow < 2.8.1 - Deserialization of Untrusted Data via XCom Poisoning
CVSS 7.5
CVE-2023-1405 HIGH
Formidable Forms <6.2 - Code Injection
CVSS 7.5
CVE-2023-6049 CRITICAL
Estatik Real Estate Plugin <4.1.1 - Code Injection
CVSS 9.8
CVE-2023-7032 HIGH
Easergy Studio < 9.3.5 - Authenticated Privilege Escalation via Deserialization of Untrusted Data
CVSS 7.8
CVE-2023-52202 CRITICAL
HTML5 MP3 Player with Folder Feedburner Playlist Free < 2.8.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
CVE-2023-52206 HIGH
Page Builder: Live Composer < 1.5.25 - PHP Object Injection via Untrusted Data Deserialization
CVSS 7.7
CVE-2023-52205 CRITICAL
HTML5 SoundCloud Player with Playlist Free < 2.8.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
CVE-2023-52200 CRITICAL
ARMember < 4.0.22 - Cross-Site Request Forgery to PHP Object Injection
CVSS 9.6
CVE-2023-6528 HIGH
Slider Revolution < 6.6.19 - Authenticated Remote Code Execution via Unsafe Slider Import
CVSS 8.8
CVE-2023-5235 HIGH
Ovic Responsive WPBakery < 1.2.9 - Authenticated Object Injection via AJAX Action
CVSS 8.8
CVE-2023-52207 CRITICAL
HTML5 MP3 Player with Playlist Free < 3.0.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
CVE-2023-52225 CRITICAL
Taggbox < 3.1 - Insecure Deserialization
CVSS 10.0
CVE-2023-52219 CRITICAL
Gecka Terms Thumbnails < 1.1 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.9
CVE-2023-52218 CRITICAL
Anton Bond Woocommerce Tranzila Payment Gateway < 1.0.8 - Unauthenticated PHP Object Injection
CVSS 10.0
CVE-2023-49442 CRITICAL
JEECG < 4.0 - Remote Code Execution via jeecgFormDemoController Deserialization
CVSS 9.8
CVE-2023-51785 HIGH
Apache InLong <1.10.0 - Deserialization
CVSS 7.5
CVE-2023-49777 CRITICAL
YITH WooCommerce Product Add-Ons <= 4.3.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
Details
Vulnerabilities 2,829
Exploit Likelihood Medium