CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,831 vulnerabilities with CWE-502
CVE-2022-28685
HIGH
AVEVA Edge 2020 SP2 Patch 4201.2111.1802.0000 - RCE
CVSS 7.8
CVE-2022-37936
CRITICAL
HPE Serviceguard for Linux < a.12.80.05 - Unauthenticated Remote Code Execution via Java Deserialization
CVSS 9.8
CVE-2022-23535
HIGH
LiteDB < 5.0.13 - Deserialization of Untrusted Data via BsonDocument _type Field
CVSS 7.3
CVE-2022-48282
MEDIUM
MongoDB C# Driver < 2.19.0 - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 6.6
CVE-2022-47986
CRITICAL
KEV
IBM Aspera Faspex < 4.4.2 PL2 - Remote Code Execution via YAML Deserialization
CVSS 9.8
CVE-2022-47507
HIGH
SolarWinds Orion Platform - Remote Code Execution via Deserialization of Untrusted Data
CVSS 7.2
CVE-2022-47504
HIGH
SolarWinds Orion Platform - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2022-47503
HIGH
SolarWinds Orion Platform - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2022-38111
HIGH
SolarWinds Platform - Code Injection
CVSS 7.2
CVE-2022-3568
HIGH
ImageMagick Engine <1.7.5 - Open Redirect
CVSS 8.8
CVE-2022-45982
CRITICAL
thinkphp 6.0.0-6.0.13 and 6.1.0-6.1.1 - Remote Code Execution via Deserialization
CVSS 9.8
CVE-2022-44645
HIGH
Apache Linkis <= 1.3.0 - Remote Code Execution via MySQL Connector/J Deserialization
CVSS 8.8
CVE-2022-32521
HIGH
Schneider Electric Data Center Expert < 7.9.0 - Remote Code Execution via Unsafe Deserialization
CVSS 7.1
CVE-2022-31710
HIGH
vRealize Log Insight 3.0-4.8 - Unauthenticated Denial of Service via Deserialization
CVSS 7.5
CVE-2022-45923
HIGH
OpenText Extended ECM 20.4-22.3 - Remote Code Execution via cs.exe Memory Manipulation
CVSS 8.8
CVE-2022-4890
MEDIUM
abhilash1985 PredictApp - Deserialization
CVSS 6.3
CVE-2022-46478
CRITICAL
datax-web <2.1.2 - Command Injection
CVSS 9.8
CVE-2022-41778
CRITICAL
Delta Electronics InfraSuite Device Master <00.00.01a - Code Injection
CVSS 9.8
CVE-2022-47083
HIGH
Spitfire CMS <1.0.475 - Code Injection
CVSS 8.8
CVE-2022-41966
HIGH
XStream < 1.4.20 - Denial of Service via Recursive Hash Calculation
CVSS 8.2
CVE-2022-41596
HIGH
HarmonyOS < 2.1 - Unauthorized Component Startup via Deserialization Inconsistency
CVSS 7.5
CVE-2022-44351
CRITICAL
skycaiji 2.5.1 - Deserialization of Untrusted Data via Mystore.php
CVSS 9.8
CVE-2022-44371
CRITICAL
hope-boot 1.0.0 - Remote Code Execution via Untrusted Deserialization
CVSS 9.8
CVE-2022-32224
CRITICAL
Activerecord < 5.2.8.1 - Insecure Deserialization
CVSS 9.8
CVE-2022-46366
CRITICAL
Apache Tapestry 3.x - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
Details
Vulnerabilities
2,831
Exploit Likelihood
Medium