CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2022-37022
HIGH
Apache Geode < 1.12.2 and 1.13.2 - Deserialization of Untrusted Data via JMX over RMI
CVSS 8.8
CVE-2022-37021
CRITICAL
Apache Geode <= 1.12.5, 1.13.4, 1.14.0 - Deserialization of Untrusted Data via JMX over RMI
CVSS 9.8
CVE-2022-34668
CRITICAL
NVFLARE < 2.1.4 - Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2022-36119
HIGH
Blue Prism Enterprise <7.01 - Code Injection
CVSS 8.8
CVE-2022-2465
HIGH
Rockwell Automation ISaGRAF Workbench 6.0-6.6.9 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.6
CVE-2022-33900
MEDIUM
PHP Object Injection - Code Injection
CVSS 4.1
CVE-2022-29805
CRITICAL
Fishbowl < 2022.4.1 - Remote Code Execution via XML Deserialization
CVSS 9.8
CVE-2022-2886
MEDIUM
Laravel 5.1.0-5.1.45 - Deserialization of Untrusted Data
CVSS 5.0
CVE-2022-2870
MEDIUM
Laravel 5.1.0-5.1.45 - Deserialization of Untrusted Data
CVSS 4.1
CVE-2022-36006
HIGH
Arvados < 2.4.2 - Authenticated Remote Code Execution via JSON Payload Deserialization
CVSS 7.9
CVE-2022-33947
MEDIUM
BIG-IP <16.1.3,15.1.6.1,14.1.5,13.1.x - Privilege Escalation
CVSS 5.4
CVE-2022-28684
HIGH
DevExpress 18.1.0-18.1.17 - Authenticated Remote Code Execution via SafeBinaryFormatter Deserialization
CVSS 8.8
CVE-2022-35223
CRITICAL
EasyUse MailHunter Ultimate < 2020 - Unauthenticated Remote Code Execution via Cookie Deserialization
CVSS 9.8
CVE-2022-30287
HIGH
Horde Groupware Webmail Edition <= 5.2.22 - Remote Code Execution via PHP Object Deserialization
CVSS 8.0
CVE-2022-35872
HIGH
Inductive Automation Ignition 8.1.15 - Code Injection
CVSS 7.8
CVE-2022-35870
HIGH
Inductive Automation Ignition 8.1.15 - Deserialization
CVSS 7.8
CVE-2022-33320
HIGH
Mitsubishi Electric GENESIS64 <10.97.1 - Code Injection
CVSS 7.8
CVE-2022-33318
CRITICAL
Mitsubishi Electric - Use After Free
CVSS 9.8
CVE-2022-33316
HIGH
Mitsubishi Electric GENESIS64 <10.97.1 - Code Injection
CVSS 7.8
CVE-2022-33315
HIGH
Mitsubishi Electric GENESIS64 <10.97.1 - Code Injection
CVSS 7.8
CVE-2022-21549
MEDIUM
Oracle Java SE <17.0.3.1 & Oracle GraalVM EE <22.1.0 - Unauthentica...
CVSS 5.3
CVE-2022-27580
HIGH
Safety Designer <= 1.11.0 - Remote Code Execution via Malicious Project File Deserialization
CVSS 7.8
CVE-2022-27579
HIGH
Flexi Soft Designer <= 1.9.4 SP1 - Remote Code Execution via Malicious Project File Deserialization
CVSS 7.8
CVE-2022-35405
CRITICAL
KEV
ManageEngine Password Manager Pro <12101 & PAM360 <5510 - RCE via Java Deserialization
CVSS 9.8
CVE-2022-24082
CRITICAL
Pega Infinity 8.1.0-8.7.3 - Remote Code Execution via JMX Interface Deserialization
CVSS 9.8
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium