CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2022-21445
CRITICAL
KEV
Oracle ADF 12.2.1.3.0/12.2.1.4.0 - RCE via Deserialization
CVSS 9.8
CVE-2022-27158
CRITICAL
PHP Pearweb < 1.32.0 - Insecure Deserialization
CVSS 9.8
CVE-2022-24846
CRITICAL
GeoWebCache < 1.19.3 - Remote Code Execution via JNDI Lookup in Disk Quota Mechanism
CVSS 9.1
CVE-2022-22958
HIGH
VMware Workspace ONE Access, Identity Manager, vRealize Automation - Remote Code Execution via JDBC URI Deserialization
CVSS 7.2
CVE-2022-22957
HIGH
VMware Workspace ONE Access and Identity Manager - Remote Code Execution via JDBC URI Deserialization
CVSS 7.2
CVE-2022-23450
CRITICAL
SIMATIC Energy Manager Basic and PRO < 7.3 Update 1 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2022-20763
MEDIUM
Cisco Webex Meetings - Code Injection
CVSS 5.4
CVE-2022-1032
HIGH
crater < 6.0.6 - Remote Code Execution via Insecure Deserialization
CVSS 7.2
CVE-2022-26503
HIGH
Veeam Agent for Windows <5.x - Code Injection
CVSS 7.8
CVE-2022-0749
HIGH
SinGooCMS.Utility - Deserialization of Untrusted Data via BinaryFormatter
CVSS 7.4
CVE-2022-23940
HIGH
SuiteCRM <8.0.1 - Authenticated RCE
CVSS 8.8
CVE-2022-24282
HIGH
SINEC NMS < 2.0 and < 1.0.3 and SINEMA Server V14 - Remote Code Execution via Insecure JSON Deserialization
CVSS 7.2
CVE-2022-21828
HIGH
Ivanti Incapptic Connect 1.35.3-1.40.0 - Authenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 7.2
CVE-2022-0138
HIGH
Airspan Mimosa Management Platform <1.0.3 / C6x/C5x/C5c <2.8.6.1 / A5x <2.5.4.1 - Untrusted Data Deserialization
CVSS 7.5
CVE-2022-24289
HIGH
Apache Cayenne <4.1 - Code Injection
CVSS 8.8
CVE-2022-22005
HIGH
Microsoft SharePoint Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.8
CVE-2022-0538
HIGH
Jenkins < 2.334 and LTS < 2.319.3 - Deserialization of Untrusted Data
CVSS 7.5
CVE-2022-21341
MEDIUM
Oracle GraalVM Enterprise Edition 20.3.4 and 21.3.0 - Unauthenticated Partial Denial of Service via Serialization
CVSS 5.3
CVE-2022-23307
HIGH
Apache Chainsaw < 2.1.0 - Deserialization of Untrusted Data
CVSS 8.8
CVE-2022-23302
HIGH
Apache Log4j 1.x - Deserialization of Untrusted Data via JMSSink Configuration
CVSS 8.8
CVE-2022-21663
MEDIUM
WordPress < 5.8.3 - Authenticated Object Injection via Multisite Super Admin Role
CVSS 6.6
CVE-2022-21647
HIGH
CodeIgniter 4.0.0-4.1.5 - Deserialization of Untrusted Data via old() Function
CVSS 7.7
CVE-2021-27017
MEDIUM
Puppet Agent <7.4.0 - Deserialization
CVSS 6.6
CVE-2021-3838
CRITICAL
dompdf < 2.0.0 - Remote Code Execution via PHAR Deserialization
CVSS 9.8
CVE-2021-4451
MEDIUM
NinjaFirewall < 4.3.3 - Authenticated PHAR Deserialization
CVSS 6.6
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium