CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,835 vulnerabilities with CWE-502
CVE-2022-44351 CRITICAL
skycaiji 2.5.1 - Deserialization of Untrusted Data via Mystore.php
CVSS 9.8
CVE-2022-44371 CRITICAL
hope-boot 1.0.0 - Remote Code Execution via Untrusted Deserialization
CVSS 9.8
CVE-2022-32224 CRITICAL
Activerecord < 5.2.8.1 - Insecure Deserialization
CVSS 9.8
CVE-2022-46366 CRITICAL
Apache Tapestry 3.x - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2022-1471 HIGH
PyTorch Model Server Registration and Deserialization RCE
CVSS 8.3
CVE-2022-36964 HIGH
SolarWinds Orion Platform - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2022-41958 HIGH
super_xray < 0.7 - Deserialization of Untrusted Data via YAML Config File
CVSS 7.3
CVE-2022-41875 CRITICAL
Optica < 0.10.2 - Unauthenticated Remote Code Execution via JSON Payload Deserialization
CVSS 10.0
CVE-2022-41922 HIGH
Yii < 1.1.27 - Remote Code Execution via Unsafe Unserialize
CVSS 8.1
CVE-2022-3861 HIGH
Betheme Theme <26.5.1.4 - Code Injection
CVSS 8.8
CVE-2022-3525 HIGH
librenms/librenms <22.10.0 - Deserialization
CVSS 8.8
CVE-2022-45077 MEDIUM
Betheme <= 26.5.1.4 - Authenticated PHP Object Injection
CVSS 6.3
CVE-2022-45047 CRITICAL
Apache MINA SSHD <= 2.9.1 - Deserialization of Untrusted Data in SimpleGeneratorHostKeyProvider
CVSS 9.8
CVE-2022-45136 CRITICAL
Apache Jena SDB < 3.17.0 - Remote Code Execution via JDBC Deserialization
CVSS 9.8
CVE-2022-38652 CRITICAL
VMWare Hyperic Agent 5.8.6 - Deserialization
CVSS 9.9
CVE-2022-38650 CRITICAL
VMware Hyperic Server <5.8.6 - Open Redirect
CVSS 10.0
CVE-2022-44562 CRITICAL
Huawei EMUI and HarmonyOS - Deserialization of Untrusted Data in System Framework Layer
CVSS 9.8
CVE-2022-44559 CRITICAL
HarmonyOS - Privilege Escalation via AMS Module Deserialization Mismatch
CVSS 9.8
CVE-2022-44558 CRITICAL
HarmonyOS and EMUI - Privilege Escalation via AMS Module Deserialization
CVSS 9.8
CVE-2022-41203 HIGH
SAP BusinessObjects BI Platform - Deserialization
CVSS 8.8
CVE-2022-32601 HIGH
Android - Local Privilege Escalation via Telephony Parcel Format Mismatch
CVSS 7.8
CVE-2022-31199 CRITICAL KEV
Netwrix Auditor < 10.5 - Unauthenticated Remote Code Execution via User Activity Video Recording Component
CVSS 9.8
CVE-2022-3536 HIGH
WooCommerce WordPress <1.6.3 - Code Injection
CVSS 8.8
CVE-2022-42919 HIGH
Python 3.9.x < 3.9.16 and 3.10.x < 3.10.9 - Privilege Escalation via Pickle Deserialization
CVSS 7.8
CVE-2022-43567 HIGH
Splunk Enterprise <8.2.9-9.0.2 - Command Injection
CVSS 8.8
Details
Vulnerabilities 2,835
Exploit Likelihood Medium