CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2021-31681
HIGH
yolov3 - Remote Code Execution via YAML Deserialization
CVSS 7.8
CVE-2021-31680
HIGH
yolov5 - Remote Code Execution via YAML Deserialization
CVSS 7.8
CVE-2021-28254
CRITICAL
Laravel 8.5.9 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2021-32828
MEDIUM
Nuxeo < 11.5.109 - Reflected Cross-Site Scripting and Remote Code Execution via OAuth2 REST API
CVSS 5.4
CVE-2021-32824
CRITICAL
Apache Dubbo < 2.6.10 - Unauthenticated Remote Code Execution via Telnet Handler Bean Manipulation
CVSS 9.8
CVE-2021-38241
CRITICAL
Ruoyi < 4.6.1 - Remote Code Execution via Shiro Weak Cipher Deserialization
CVSS 9.8
CVE-2021-33420
CRITICAL
inikulin replicator <1.0.4 - Code Injection
CVSS 9.8
CVE-2021-25642
HIGH
Apache Hadoop 2.9.0-2.10.1 - Remote Code Execution via ZKConfigurationStore Deserialization
CVSS 8.8
CVE-2021-4178
MEDIUM
fabric8-kubernetes 5.0.0-beta-1-5.0.3 - Arbitrary Code Execution via YAML Parsing
CVSS 6.7
CVE-2021-4125
HIGH
OpenShift 4.6.0-4.6.51 - Deserialization of Untrusted Data in Metering Hive Container
CVSS 8.1
CVE-2021-41419
CRITICAL
QVIS DVR and NVR Firmware < 2021-12-13 - Remote Code Execution via Java Deserialization
CVSS 9.8
CVE-2021-36665
HIGH
Druva inSync Client < 7.0.0 - Local Privilege Escalation via inSyncUpgradeDaemon
CVSS 7.8
CVE-2021-35095
HIGH
Snapdragon Connectivity - Snapdragon Mobile - Use After Free
CVSS 8.4
CVE-2021-32935
HIGH
Cognex In-Sight OPC Server <5.7.4 - Deserialization
CVSS 8.8
CVE-2021-23592
HIGH
thinkphp < 6.0.12 - Deserialization of Untrusted Data via Insecure Unserialize Method
CVSS 7.7
CVE-2021-21956
HIGH
CloudLinux Imunify360 5.10.2 - Remote Code Execution via Ai-Bolit PHP Unserialize
CVSS 7.8
CVE-2021-33207
CRITICAL
MashZone NextGen <10.7 - Deserialization
CVSS 9.8
CVE-2021-27475
HIGH
Rockwellautomation Connected Components Workbench < 12.00.00 - Insecure Deserialization
CVSS 8.6
CVE-2021-27470
CRITICAL
Rockwell Automation FactoryTalk AssetCentre <10.00 - Deserialization
CVSS 10.0
CVE-2021-27466
CRITICAL
Rockwell Automation FactoryTalk AssetCentre <10.00 - Open Redirect
CVSS 10.0
CVE-2021-27462
CRITICAL
Rockwell Automation FactoryTalk AssetCentre <10.00 - Open Redirect
CVSS 10.0
CVE-2021-27460
CRITICAL
Rockwell Automation FactoryTalk AssetCentre <10.00 - Deserialization
CVSS 10.0
CVE-2021-46364
HIGH
Magnolia CMS < 6.2.4 - Remote Code Execution via Snake YAML Deserialization
CVSS 7.8
CVE-2021-42631
HIGH
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 8.1
CVE-2021-45899
CRITICAL
SuiteCRM <7.12.3, <8.0.2 - Code Injection
CVSS 9.8
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium