CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,831 vulnerabilities with CWE-502
CVE-2023-28115
CRITICAL
Snappy < 1.4.2 - Remote Code Execution via PHAR Deserialization in file_exists()
CVSS 9.8
CVE-2023-26464
HIGH
Apache Log4j < 2.0 - Denial of Service via Chainsaw or SocketAppender Deserialization
CVSS 7.5
CVE-2023-23638
MEDIUM
Apache Dubbo 2.7.0-2.7.21, 3.0.0-3.0.13, 3.1.0-3.1.5 - Remote Code Execution via Generic Invoke Deserialization
CVSS 5.0
CVE-2023-26779
CRITICAL
CleverStupidDog yf-exam <1.8.0 - Deserialization
CVSS 9.8
CVE-2023-27372
CRITICAL
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
CVSS 9.8
CVE-2023-20944
HIGH
Android - Local Privilege Escalation via Unsafe Deserialization in ChooseTypeAndAccountActivity
CVSS 7.8
CVE-2023-26326
CRITICAL
BuddyForms <2.7.8 - Insecure Deserialization
CVSS 9.8
CVE-2023-0960
MEDIUM
SeaCMS 11.6 - Deserialization of Untrusted Data in Picture Management
CVSS 4.7
CVE-2023-26234
MEDIUM
JD-GUI 1.6.6 - Deserialization of Untrusted Data via UIMainWindowPreferencesProvider
CVSS 6.6
CVE-2023-23836
HIGH
SolarWinds Platform <2022.4.1 - Deserialization
CVSS 7.2
CVE-2023-21713
HIGH
Microsoft SQL Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2023-21710
HIGH
Microsoft Exchange Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2023-21707
HIGH
Microsoft Exchange Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2023-21706
HIGH
Microsoft Exchange Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2023-21703
MEDIUM
Azure Data Box Gateway and Azure Stack Edge - Remote Code Execution via Untrusted Data Deserialization
CVSS 6.5
CVE-2023-21568
HIGH
Microsoft SQL Server Integration Service - RCE
CVSS 7.3
CVE-2023-21529
HIGH
KEV
Microsoft Exchange Server - Remote Code Execution
CVSS 8.8
CVE-2023-25558
HIGH
DataHub < 0.9.5 - Remote Code Execution via Unsafe id_token Deserialization
CVSS 7.5
CVE-2023-25194
HIGH
Apache Kafka Connect 2.3.0-3.3.1 - Authenticated Remote Code Execution via SASL JAAS Config Deserialization
CVSS 8.8
CVE-2023-0669
HIGH
KEV
Fortra GoAnywhere MFT Unsafe Deserialization RCE
CVSS 7.2
CVE-2023-25135
CRITICAL
vBulletin < 5.6.9 PL1 - Unauthenticated Remote Code Execution via Deserialization
CVSS 9.8
CVE-2023-24997
CRITICAL
Apache InLong 1.1.0-1.5.0 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2023-24162
CRITICAL
Dromara Hutool <5.8.11 - Code Injection
CVSS 9.8
CVE-2023-21839
HIGH
KEV
Oracle WebLogic Server <14.1.1.0.0 - RCE
CVSS 7.5
CVE-2023-22850
HIGH
Tiki < 24.1 - PHP Object Injection via Spreadsheets Feature
CVSS 8.8
Details
Vulnerabilities
2,831
Exploit Likelihood
Medium