CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2022-44351
CRITICAL
skycaiji 2.5.1 - Deserialization of Untrusted Data via Mystore.php
CVSS 9.8
CVE-2022-44371
CRITICAL
hope-boot 1.0.0 - Remote Code Execution via Untrusted Deserialization
CVSS 9.8
CVE-2022-32224
CRITICAL
Activerecord < 5.2.8.1 - Insecure Deserialization
CVSS 9.8
CVE-2022-46366
CRITICAL
Apache Tapestry 3.x - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2022-1471
HIGH
PyTorch Model Server Registration and Deserialization RCE
CVSS 8.3
CVE-2022-36964
HIGH
SolarWinds Orion Platform - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2022-41958
HIGH
super_xray < 0.7 - Deserialization of Untrusted Data via YAML Config File
CVSS 7.3
CVE-2022-41875
CRITICAL
Optica < 0.10.2 - Unauthenticated Remote Code Execution via JSON Payload Deserialization
CVSS 10.0
CVE-2022-41922
HIGH
Yii < 1.1.27 - Remote Code Execution via Unsafe Unserialize
CVSS 8.1
CVE-2022-3861
HIGH
Betheme Theme <26.5.1.4 - Code Injection
CVSS 8.8
CVE-2022-3525
HIGH
librenms/librenms <22.10.0 - Deserialization
CVSS 8.8
CVE-2022-45077
MEDIUM
Betheme <= 26.5.1.4 - Authenticated PHP Object Injection
CVSS 6.3
CVE-2022-45047
CRITICAL
Apache MINA SSHD <= 2.9.1 - Deserialization of Untrusted Data in SimpleGeneratorHostKeyProvider
CVSS 9.8
CVE-2022-45136
CRITICAL
Apache Jena SDB < 3.17.0 - Remote Code Execution via JDBC Deserialization
CVSS 9.8
CVE-2022-38652
CRITICAL
VMWare Hyperic Agent 5.8.6 - Deserialization
CVSS 9.9
CVE-2022-38650
CRITICAL
VMware Hyperic Server <5.8.6 - Open Redirect
CVSS 10.0
CVE-2022-44562
CRITICAL
Huawei EMUI and HarmonyOS - Deserialization of Untrusted Data in System Framework Layer
CVSS 9.8
CVE-2022-44559
CRITICAL
HarmonyOS - Privilege Escalation via AMS Module Deserialization Mismatch
CVSS 9.8
CVE-2022-44558
CRITICAL
HarmonyOS and EMUI - Privilege Escalation via AMS Module Deserialization
CVSS 9.8
CVE-2022-41203
HIGH
SAP BusinessObjects BI Platform - Deserialization
CVSS 8.8
CVE-2022-32601
HIGH
Android - Local Privilege Escalation via Telephony Parcel Format Mismatch
CVSS 7.8
CVE-2022-31199
CRITICAL
KEV
Netwrix Auditor < 10.5 - Unauthenticated Remote Code Execution via User Activity Video Recording Component
CVSS 9.8
CVE-2022-3536
HIGH
WooCommerce WordPress <1.6.3 - Code Injection
CVSS 8.8
CVE-2022-42919
HIGH
Python 3.9.x < 3.9.16 and 3.10.x < 3.10.9 - Privilege Escalation via Pickle Deserialization
CVSS 7.8
CVE-2022-43567
HIGH
Splunk Enterprise <8.2.9-9.0.2 - Command Injection
CVSS 8.8
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium