CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,835 vulnerabilities with CWE-502
CVE-2021-39392
CRITICAL
MyLittleBackup <= 1.7 - Remote Code Execution via Hardcoded MachineKey Deserialization
CVSS 9.8
CVE-2021-37181
CRITICAL
Siemens Cerberus DMS and Desigo CC - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 10.0
CVE-2021-39207
HIGH
ParlAI < 1.1.0 - Remote Code Execution via YAML Deserialization
CVSS 8.4
CVE-2021-24040
CRITICAL
ParlAI < 1.1.0 - Remote Code Execution via Unsafe YAML Deserialization
CVSS 9.8
CVE-2021-37579
CRITICAL
Apache Dubbo 2.7.0-2.7.12 - Deserialization of Untrusted Data via Security Check Bypass
CVSS 9.8
CVE-2021-32836
HIGH
ZStack <3.10.12-4.1.6 - Open Redirect
CVSS 7.5
CVE-2021-35217
HIGH
Patch Manager Orion Platform - Code Injection
CVSS 8.9
CVE-2021-36163
CRITICAL
Apache Dubbo 2.7.0-2.7.12 - Deserialization of Untrusted Data via Hessian Protocol
CVSS 9.8
CVE-2021-32568
HIGH
mrdoc < 0.7.0 - Deserialization of Untrusted Data
CVSS 7.8
CVE-2021-35218
HIGH
SolarWinds Orion Platform < 2020.2.6 - Unauthenticated Remote Code Execution via Web Console Chart Endpoint
CVSS 8.9
CVE-2021-35216
HIGH
SolarWinds Patch Manager < 2020.2.6 - Authenticated Remote Code Execution via Insecure Deserialization
CVSS 8.9
CVE-2021-35215
HIGH
SolarWinds Orion Platform < 2020.2.5 - Authenticated Remote Code Execution via Insecure Deserialization
CVSS 8.9
CVE-2021-36231
HIGH
MIK.starlight <7.9.5.24363 - Code Injection
CVSS 8.8
CVE-2021-21677
HIGH
Jenkins Code Coverage API Plugin < 1.4.0 - Remote Code Execution via Untrusted Java Deserialization
CVSS 8.8
CVE-2021-36981
HIGH
verinice < 1.22.2 - Authenticated Remote Code Execution via Unsafe Java Deserialization
CVSS 8.8
CVE-2021-39132
HIGH
Rundeck < 3.3.14 and 3.4.0-3.4.3 - Authenticated Remote Code Execution via Untrusted Plugin or ACL Policy Upload
CVSS 8.8
CVE-2021-34066
CRITICAL
EdgeGallery/developer-be < 1.0 - Remote Code Execution via YAML Deserialization
CVSS 9.8
CVE-2021-21741
CRITICAL
ZTE ZXV10 M910 Firmware - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2021-24579
HIGH
Bold Page Builder < 3.1.6 - PHP Object Injection via bt_bb_get_grid AJAX Action
CVSS 8.8
CVE-2021-21869
HIGH
CODESYS Development System 3.5.16-3.5.17 - Remote Code Execution via Unsafe Deserialization in ProfileData
CVSS 7.8
CVE-2021-31010
HIGH
KEV
iPadOS < 14.8 - Sandbox Escape via Deserialization Issue
CVSS 7.5
CVE-2021-39152
HIGH
XStream < 1.4.18 - Remote Code Execution via Deserialization
CVSS 8.5
CVE-2021-39150
HIGH
Oracle Utilities Framework < 1.4.18 - SSRF
CVSS 8.5
CVE-2021-39140
MEDIUM
XStream < 1.4.18 - Denial of Service via CPU Exhaustion
CVSS 6.5
CVE-2021-39154
HIGH
XStream < 1.4.18 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.5
Details
Vulnerabilities
2,835
Exploit Likelihood
Medium