CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,829 vulnerabilities with CWE-502
CVE-2023-27459
HIGH
WPEverest User Registration < 2.3.2.1 - Authenticated PHP Object Injection
CVSS 7.4
CVE-2023-51518
CRITICAL
Apache James <3.7.5, 3.8.0 - Privilege Escalation
CVSS 9.8
CVE-2023-51389
CRITICAL
Hertzbeat < 1.4.1 - Deserialization of Untrusted Data via SnakeYAML Parser
CVSS 9.8
CVE-2023-52357
HIGH
Huawei EMUI and HarmonyOS - Denial of Service via Serialization/Deserialization Mismatch
CVSS 7.5
CVE-2023-40057
CRITICAL
SolarWinds Access Rights Manager < 2023.2.2 - Authenticated Remote Code Execution via Deserialization
CVSS 9.0
CVE-2023-26592
LOW
Intel(R) Thunderbolt(TM) DCH <88 - DoS
CVSS 3.8
CVE-2023-46615
MEDIUM
KD Coming Soon < 1.7 - PHP Object Injection via Untrusted Data Deserialization
CVSS 5.4
CVE-2023-6933
HIGH
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection via Untrusted Input Deserialization
CVSS 8.8
CVE-2023-50943
HIGH
Apache Airflow < 2.8.1 - Deserialization of Untrusted Data via XCom Poisoning
CVSS 7.5
CVE-2023-1405
HIGH
Formidable Forms <6.2 - Code Injection
CVSS 7.5
CVE-2023-6049
CRITICAL
Estatik Real Estate Plugin <4.1.1 - Code Injection
CVSS 9.8
CVE-2023-7032
HIGH
Easergy Studio < 9.3.5 - Authenticated Privilege Escalation via Deserialization of Untrusted Data
CVSS 7.8
CVE-2023-52202
CRITICAL
HTML5 MP3 Player with Folder Feedburner Playlist Free < 2.8.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
CVE-2023-52206
HIGH
Page Builder: Live Composer < 1.5.25 - PHP Object Injection via Untrusted Data Deserialization
CVSS 7.7
CVE-2023-52205
CRITICAL
HTML5 SoundCloud Player with Playlist Free < 2.8.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
CVE-2023-52200
CRITICAL
ARMember < 4.0.22 - Cross-Site Request Forgery to PHP Object Injection
CVSS 9.6
CVE-2023-6528
HIGH
Slider Revolution < 6.6.19 - Authenticated Remote Code Execution via Unsafe Slider Import
CVSS 8.8
CVE-2023-5235
HIGH
Ovic Responsive WPBakery < 1.2.9 - Authenticated Object Injection via AJAX Action
CVSS 8.8
CVE-2023-52207
CRITICAL
HTML5 MP3 Player with Playlist Free < 3.0.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
CVE-2023-52225
CRITICAL
Taggbox < 3.1 - Insecure Deserialization
CVSS 10.0
CVE-2023-52219
CRITICAL
Gecka Terms Thumbnails < 1.1 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.9
CVE-2023-52218
CRITICAL
Anton Bond Woocommerce Tranzila Payment Gateway < 1.0.8 - Unauthenticated PHP Object Injection
CVSS 10.0
CVE-2023-49442
CRITICAL
JEECG < 4.0 - Remote Code Execution via jeecgFormDemoController Deserialization
CVSS 9.8
CVE-2023-51785
HIGH
Apache InLong <1.10.0 - Deserialization
CVSS 7.5
CVE-2023-49777
CRITICAL
YITH WooCommerce Product Add-Ons <= 4.3.0 - PHP Object Injection via Untrusted Data Deserialization
CVSS 9.1
Details
Vulnerabilities
2,829
Exploit Likelihood
Medium