CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,830 vulnerabilities with CWE-502
CVE-2023-37390 HIGH
Themesflat Addons For Elementor < 2.0.0 - Unauthenticated PHP Object Injection
CVSS 8.3
CVE-2023-6730 HIGH
huggingface/transformers < 4.36.0 - Deserialization of Untrusted Data
CVSS 8.8
CVE-2023-49819 HIGH
Structured Content (JSON-LD) #wpsc < 1.5.3 - PHP Object Injection via Untrusted Data Deserialization
CVSS 7.5
CVE-2023-46154 MEDIUM
E2Pdf - Export To Pdf Tool for WordPress <= 1.20.18 - PHP Object Injection
CVSS 6.6
CVE-2023-46279 CRITICAL
Apache Dubbo <3.1.5 - Use After Free
CVSS 9.8
CVE-2023-29234 CRITICAL
Apache Dubbo <3.1.10, <3.2.4 - Deserialization
CVSS 9.8
CVE-2023-50252 HIGH
php-svg-lib < 0.5.1 - PHAR Deserialization via Unsanitized href Attribute in SVG use Tag
CVSS 8.3
CVE-2023-6656 MEDIUM
DeepFaceLab pretrained DF.wf.288res.384.92.72.22 - Deserialization
CVSS 5.0
CVE-2023-6654 MEDIUM
PHPEMS 6.x/7.x/8.x/9.0 - Deserialization
CVSS 6.3
CVE-2023-6580 HIGH
D-Link DIR-846 FW100A53DBR - Deserialization
CVSS 8.8
CVE-2023-49297 LOW
PyDrive2 <1.16.2 - Arbitrary Code Execution via Unsafe YAML Deserialization
CVSS 3.3
CVE-2023-46674 MEDIUM
Elasticsearch < 7.17.11 - Authenticated Remote Code Execution via Unsafe Java Deserialization
CVSS 6.0
CVE-2023-48967 CRITICAL
Ssolon <2.6.0, <2.5.12 - Deserialization
CVSS 9.8
CVE-2023-48887 CRITICAL
Jupiter 1.3.1 - Remote Code Execution via RPC Request Deserialization
CVSS 9.8
CVE-2023-48886 CRITICAL
NettyRpc 1.2 - Remote Code Execution via Deserialization
CVSS 9.8
CVE-2023-47207 CRITICAL
Delta Electronics InfraSuite Device Master 1.0.7 - Unauthenticated Remote Code Execution via Deserialization
CVSS 9.8
CVE-2023-48952 HIGH
openlink virtuoso-opensource <7.2.11 - DoS
CVSS 7.5
CVE-2023-6378 HIGH
logback 1.4.11 - Denial of Service via Serialization Vulnerability
CVSS 7.1
CVE-2023-46990 CRITICAL
PublicCMS <4.0.202302.e - Code Injection
CVSS 9.8
CVE-2023-46302 CRITICAL
Apache Submarine - YAML Deserialization
CVSS 9.8
CVE-2023-44353 CRITICAL
Adobe ColdFusion <= 2023.5 and <= 2021.11 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2023-44351 CRITICAL
Adobe ColdFusion <= 2023.5 and <= 2021.11 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2023-44350 CRITICAL
Adobe ColdFusion <= 2023.5 and <= 2021.11 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2023-47130 HIGH
Yii < 1.1.29 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.1
CVE-2023-38177 MEDIUM
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 6.1
Details
Vulnerabilities 2,830
Exploit Likelihood Medium