CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2021-23758
HIGH
ajaxpro.2 < 21.10.30.1 and AjaxNetProfessional < 21.11.29.1 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.1
CVE-2021-43360
HIGH
Sunnet eHRD - Authenticated Remote Code Execution via Deserialization
CVSS 8.8
CVE-2021-22095
MEDIUM
Spring AMQP 2.2.0-2.2.19 and 2.3.0-2.3.11 - Denial of Service via Large Message Body Deserialization
CVSS 6.5
CVE-2021-34992
HIGH
Orckestra C1 CMS 6.10 - Authenticated Remote Code Execution via Deserialization in Composite.dll
CVSS 8.8
CVE-2021-26558
HIGH
Apache ShardingSphere-UI 4.1.1-5.0.0 - Deserialization of Untrusted Data
CVSS 7.5
CVE-2021-42698
HIGH
DAQFactory - Memory Corruption via Binary Deserialization
CVSS 7.8
CVE-2021-42237
CRITICAL
KEV
Sitecore Experience Platform 7.5-8.2 Update-7 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
CVE-2021-22097
MEDIUM
Spring AMQP 2.2.0-2.2.18 and 2.3.0-2.3.10 - Denial of Service via Malicious Dictionary Deserialization
CVSS 6.5
CVE-2021-41078
HIGH
nameko < 2.13.0 - Remote Code Execution via Config File Deserialization
CVSS 7.8
CVE-2021-40865
CRITICAL
Apache Storm <2.2.1, <2.3.0, <1.2.4 - Open Redirect
CVSS 9.8
CVE-2021-40719
CRITICAL
Adobe Connect <11.2.3 - Code Injection
CVSS 9.8
CVE-2021-39321
HIGH
Sassy Social Share 3.3.23 - Authenticated PHP Object Injection via Import Config AJAX Action
CVSS 8.8
CVE-2021-35227
MEDIUM
RabbitMQ Plugin <2020.2.6 - Info Disclosure
CVSS 4.7
CVE-2021-40720
CRITICAL
Adobe ops-cli < 2.0.5 - Remote Code Execution via Deserialization in Checkout Repo Function
CVSS 9.8
CVE-2021-40843
HIGH
Proofpoint Insider Threat Management Server <7.11.2 - Deserialization
CVSS 7.3
CVE-2021-33728
HIGH
SINEC NMS < V1.0 SP2 Update 1 - Code Injection
CVSS 7.2
CVE-2021-25738
MEDIUM
kubernetes/java < 9.0.2 and io.kubernetes/client-java < 11.0.1 - Remote Code Execution via YAML Deserialization
CVSS 6.7
CVE-2021-42090
CRITICAL
Zammad < 4.1.1 - Remote Code Execution via Form Deserialization
CVSS 9.8
CVE-2021-41129
HIGH
Pterodactyl Panel 1.0.0-1.6.1 - Authentication Bypass via Two-Factor Confirmation Token Manipulation
CVSS 8.1
CVE-2021-0685
HIGH
Android - Local Privilege Escalation via Unsafe Parcel Deserialization in ParsedIntentInfo
CVSS 7.8
CVE-2021-41110
CRITICAL
cwlviewer <1.3.1 - Deserialization of Untrusted Data
CVSS 9.1
CVE-2021-41616
CRITICAL
Apache DB DdlUtils 1.0 - Deserialization of Untrusted Data via BinaryObjectsHelper
CVSS 9.8
CVE-2021-41588
HIGH
Gradle Enterprise 2017.2-2021.1.3 - Deserialization of Untrusted Data
CVSS 8.1
CVE-2021-40102
CRITICAL
Concrete CMS < 8.5.5 - Arbitrary File Deletion via PHAR Deserialization
CVSS 9.1
CVE-2021-31819
CRITICAL
Halibut < 4.4.7 - Remote Code Execution via Deserialization
CVSS 9.8
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium