CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,835 vulnerabilities with CWE-502
CVE-2022-21445 CRITICAL KEV
Oracle ADF 12.2.1.3.0/12.2.1.4.0 - RCE via Deserialization
CVSS 9.8
CVE-2022-27158 CRITICAL
PHP Pearweb < 1.32.0 - Insecure Deserialization
CVSS 9.8
CVE-2022-24846 CRITICAL
GeoWebCache < 1.19.3 - Remote Code Execution via JNDI Lookup in Disk Quota Mechanism
CVSS 9.1
CVE-2022-22958 HIGH
VMware Workspace ONE Access, Identity Manager, vRealize Automation - Remote Code Execution via JDBC URI Deserialization
CVSS 7.2
CVE-2022-22957 HIGH
VMware Workspace ONE Access and Identity Manager - Remote Code Execution via JDBC URI Deserialization
CVSS 7.2
CVE-2022-23450 CRITICAL
SIMATIC Energy Manager Basic and PRO < 7.3 Update 1 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2022-20763 MEDIUM
Cisco Webex Meetings - Code Injection
CVSS 5.4
CVE-2022-1032 HIGH
crater < 6.0.6 - Remote Code Execution via Insecure Deserialization
CVSS 7.2
CVE-2022-26503 HIGH
Veeam Agent for Windows <5.x - Code Injection
CVSS 7.8
CVE-2022-0749 HIGH
SinGooCMS.Utility - Deserialization of Untrusted Data via BinaryFormatter
CVSS 7.4
CVE-2022-23940 HIGH
SuiteCRM <8.0.1 - Authenticated RCE
CVSS 8.8
CVE-2022-24282 HIGH
SINEC NMS < 2.0 and < 1.0.3 and SINEMA Server V14 - Remote Code Execution via Insecure JSON Deserialization
CVSS 7.2
CVE-2022-21828 HIGH
Ivanti Incapptic Connect 1.35.3-1.40.0 - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2022-0138 HIGH
Airspan Mimosa Management Platform <1.0.3 / C6x/C5x/C5c <2.8.6.1 / A5x <2.5.4.1 - Untrusted Data Deserialization
CVSS 7.5
CVE-2022-24289 HIGH
Apache Cayenne <4.1 - Code Injection
CVSS 8.8
CVE-2022-22005 HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2022-0538 HIGH
Jenkins < 2.334 and LTS < 2.319.3 - Deserialization of Untrusted Data
CVSS 7.5
CVE-2022-21341 MEDIUM
Oracle GraalVM Enterprise Edition 20.3.4 and 21.3.0 - Unauthenticated Partial Denial of Service via Serialization
CVSS 5.3
CVE-2022-23307 HIGH
Apache Chainsaw < 2.1.0 - Deserialization of Untrusted Data
CVSS 8.8
CVE-2022-23302 HIGH
Apache Log4j 1.x - Deserialization of Untrusted Data via JMSSink Configuration
CVSS 8.8
CVE-2022-21663 MEDIUM
WordPress < 5.8.3 - Authenticated Object Injection via Multisite Super Admin Role
CVSS 6.6
CVE-2022-21647 HIGH
CodeIgniter 4.0.0-4.1.5 - Deserialization of Untrusted Data via old() Function
CVSS 7.7
CVE-2021-27017 MEDIUM
Puppet Agent <7.4.0 - Deserialization
CVSS 6.6
CVE-2021-3838 CRITICAL
dompdf < 2.0.0 - Remote Code Execution via PHAR Deserialization
CVSS 9.8
CVE-2021-4451 MEDIUM
NinjaFirewall < 4.3.3 - Authenticated PHAR Deserialization
CVSS 6.6
Details
Vulnerabilities 2,835
Exploit Likelihood Medium