CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,831 vulnerabilities with CWE-502
CVE-2022-28685 HIGH
AVEVA Edge 2020 SP2 Patch 4201.2111.1802.0000 - RCE
CVSS 7.8
CVE-2022-37936 CRITICAL
HPE Serviceguard for Linux < a.12.80.05 - Unauthenticated Remote Code Execution via Java Deserialization
CVSS 9.8
CVE-2022-23535 HIGH
LiteDB < 5.0.13 - Deserialization of Untrusted Data via BsonDocument _type Field
CVSS 7.3
CVE-2022-48282 MEDIUM
MongoDB C# Driver < 2.19.0 - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 6.6
CVE-2022-47986 CRITICAL KEV
IBM Aspera Faspex < 4.4.2 PL2 - Remote Code Execution via YAML Deserialization
CVSS 9.8
CVE-2022-47507 HIGH
SolarWinds Orion Platform - Remote Code Execution via Deserialization of Untrusted Data
CVSS 7.2
CVE-2022-47504 HIGH
SolarWinds Orion Platform - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2022-47503 HIGH
SolarWinds Orion Platform - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2022-38111 HIGH
SolarWinds Platform - Code Injection
CVSS 7.2
CVE-2022-3568 HIGH
ImageMagick Engine <1.7.5 - Open Redirect
CVSS 8.8
CVE-2022-45982 CRITICAL
thinkphp 6.0.0-6.0.13 and 6.1.0-6.1.1 - Remote Code Execution via Deserialization
CVSS 9.8
CVE-2022-44645 HIGH
Apache Linkis <= 1.3.0 - Remote Code Execution via MySQL Connector/J Deserialization
CVSS 8.8
CVE-2022-32521 HIGH
Schneider Electric Data Center Expert < 7.9.0 - Remote Code Execution via Unsafe Deserialization
CVSS 7.1
CVE-2022-31710 HIGH
vRealize Log Insight 3.0-4.8 - Unauthenticated Denial of Service via Deserialization
CVSS 7.5
CVE-2022-45923 HIGH
OpenText Extended ECM 20.4-22.3 - Remote Code Execution via cs.exe Memory Manipulation
CVSS 8.8
CVE-2022-4890 MEDIUM
abhilash1985 PredictApp - Deserialization
CVSS 6.3
CVE-2022-46478 CRITICAL
datax-web <2.1.2 - Command Injection
CVSS 9.8
CVE-2022-41778 CRITICAL
Delta Electronics InfraSuite Device Master <00.00.01a - Code Injection
CVSS 9.8
CVE-2022-47083 HIGH
Spitfire CMS <1.0.475 - Code Injection
CVSS 8.8
CVE-2022-41966 HIGH
XStream < 1.4.20 - Denial of Service via Recursive Hash Calculation
CVSS 8.2
CVE-2022-41596 HIGH
HarmonyOS < 2.1 - Unauthorized Component Startup via Deserialization Inconsistency
CVSS 7.5
CVE-2022-44351 CRITICAL
skycaiji 2.5.1 - Deserialization of Untrusted Data via Mystore.php
CVSS 9.8
CVE-2022-44371 CRITICAL
hope-boot 1.0.0 - Remote Code Execution via Untrusted Deserialization
CVSS 9.8
CVE-2022-32224 CRITICAL
Activerecord < 5.2.8.1 - Insecure Deserialization
CVSS 9.8
CVE-2022-46366 CRITICAL
Apache Tapestry 3.x - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
Details
Vulnerabilities 2,831
Exploit Likelihood Medium