CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2021-41766
HIGH
Apache Karaf < 4.3.6 - Deserialization of Untrusted Data via JMX
CVSS 8.1
CVE-2021-45394
HIGH
html2pdf < 5.2.4 - Deserialization of Untrusted Data via Malicious Link Tag
CVSS 8.8
CVE-2021-43297
CRITICAL
Apache Dubbo <2.6.12, <2.7.15, <3.0 - Code Injection
CVSS 9.8
CVE-2021-42392
CRITICAL
H2 < 2.0.204 - Insecure Deserialization
CVSS 9.8
CVE-2021-20318
HIGH
JBoss Enterprise Application Platform - Remote Code Execution via JMS ObjectMessage Deserialization
CVSS 7.2
CVE-2021-4118
HIGH
pytorch_lightning < 1.6.0 - Remote Code Execution via Pickle Deserialization
CVSS 7.8
CVE-2021-43853
HIGH
Ajax.NET Professional < 21.12.22.1 - JavaScript Object Injection via JSON Parsing
CVSS 8.7
CVE-2021-44029
CRITICAL
Quest KACE Desktop Authority < 11.2 - Remote Code Execution via RadAsyncUpload Deserialization
CVSS 9.8
CVE-2021-36336
CRITICAL
Wyse Management Suite <3.3.1 - Code Injection
CVSS 9.8
CVE-2021-42550
MEDIUM
qos logback < 1.2.7 - Deserialization of Untrusted Data via LDAP
CVSS 6.6
CVE-2021-0970
HIGH
Android - Local Privilege Escalation via Parcel Deserialization Mismatch
CVSS 7.8
CVE-2021-4104
HIGH
Apache Log4j 1.2 - Remote Code Execution via JMSAppender JNDI Requests
CVSS 7.5
CVE-2021-24857
CRITICAL
ToTop Link WP <1.7.1 - Code Injection
CVSS 9.8
CVE-2021-44228
CRITICAL
KEV
Log4Shell HTTP Header Injection
CVSS 10.0
CVE-2021-42130
HIGH
Ivanti Avalanche < 6.3.3 - Remote Code Execution via Deserialization of Untrusted Data
CVSS 8.8
CVE-2021-42127
CRITICAL
Ivanti Avalanche < 6.3.3 - Remote Code Execution via Data Repository Service
CVSS 9.8
CVE-2021-42125
HIGH
Ivanti Avalanche < 6.3.3 - Unauthenticated Arbitrary File Write via Inforail Service
CVSS 8.8
CVE-2021-44682
CRITICAL
Veritas Enterprise Vault < 14.1.2 - Deserialization of Untrusted Data via .NET Remoting TCP Ports
CVSS 9.8
CVE-2021-44681
CRITICAL
Veritas Enterprise Vault < 14.1.2 - Deserialization of Untrusted Data via .NET Remoting TCP Ports
CVSS 9.8
CVE-2021-44680
CRITICAL
Veritas Enterprise Vault < 14.1.2 - Deserialization of Untrusted Data via .NET Remoting TCP Ports
CVSS 9.8
CVE-2021-44679
CRITICAL
Veritas Enterprise Vault < 14.1.2 - Deserialization of Untrusted Data via .NET Remoting TCP Ports
CVSS 9.8
CVE-2021-44678
CRITICAL
Veritas Enterprise Vault < 14.1.2 - Deserialization of Untrusted Data via .NET Remoting TCP Ports
CVSS 9.8
CVE-2021-44677
CRITICAL
Veritas Enterprise Vault < 14.1.2 - Deserialization of Untrusted Data via .NET Remoting TCP Ports
CVSS 9.8
CVE-2021-36567
CRITICAL
ThinkPHP 6.0.8 - Deserialization of Untrusted Data via League Flysystem AbstractCache
CVSS 9.8
CVE-2021-36564
CRITICAL
ThinkPHP < 6.0.9 - Deserialization of Untrusted Data via Flysystem Cached Adapter
CVSS 9.8
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium