CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,841 vulnerabilities with CWE-502
CVE-2021-22855
CRITICAL
HR Portal - Remote Code Execution via Untrusted Deserialization
CVSS 9.8
CVE-2021-23338
MEDIUM
qlib < 0.7.0 - Remote Code Execution via Unsafe YAML Deserialization
CVSS 6.6
CVE-2021-27213
CRITICAL
pystemon < 2021-02-13 - Remote Code Execution via YAML Deserialization
CVSS 9.8
CVE-2021-26915
HIGH
NetMotion Mobility < 11.73 & 12.x < 12.02 - RCE via Java Deserialization in StatusServlet
CVSS 8.1
CVE-2021-26914
HIGH
NetMotion Mobility < 11.73 and 12.x < 12.02 - Unauthenticated Remote Code Execution via Java Deserialization in MvcUtil
CVSS 8.1
CVE-2021-26913
HIGH
NetMotion Mobility < 11.73 and 12.x < 12.02 - Remote Code Execution via Java Deserialization
CVSS 8.1
CVE-2021-26912
HIGH
NetMotion Mobility <11.73/12.x<12.02 - RCE via Java Deserialization
CVSS 8.1
CVE-2021-25274
CRITICAL
SolarWinds Orion Platform <2020.2.4 - RCE
CVSS 9.8
CVE-2021-25758
HIGH
JetBrains IntelliJ IDEA < 2020.3 - Local Code Execution via Insecure Workspace Model Deserialization
CVSS 7.8
CVE-2021-3160
CRITICAL
ACA ASSUREX RENTES ASSUWEB 359.3 build 1 - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2021-20190
HIGH
jackson-databind < 2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
CVE-2021-25294
CRITICAL
OpenCATS <= 0.9.5-3 - Remote Code Execution via Unsafe Deserialization in DataGrid Activity Parameter
CVSS 9.8
CVE-2021-21249
CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via SnakeYAML Deserialization
CVSS 9.6
CVE-2021-21247
CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via AJAX Event Listener Deserialization
CVSS 9.6
CVE-2021-21242
CRITICAL
OneDev < 4.0.3 - Unauthenticated Remote Code Execution via Attachment-Support Header Deserialization
CVSS 10.0
CVE-2021-21243
CRITICAL
OneDev <4.0.3 - Pre-Auth Code Injection
CVSS 10.0
CVE-2021-21604
HIGH
Jenkins < 2.263.1, < 2.274 - Deserialization of Untrusted Data via Old Data Monitor
CVSS 8.0
CVE-2021-3007
CRITICAL
Laminas Project laminas-http <2.14.2 - Code Injection
CVSS 9.8
CVE-2020-37071
CRITICAL
CraftCMS 3 vCard Plugin 1.0.0 - Code Injection
CVSS 9.8
CVE-2020-19559
CRITICAL
Diebold Aglis XFS for Opteva 4.1.61.1 - Remote Code Execution via ResolveMethod() Parameter
CVSS 9.8
CVE-2020-36727
CRITICAL
Newsletter Manager <1.5.1 - Open Redirect
CVSS 9.8
CVE-2020-36726
CRITICAL
Ultimate Reviews <2.1.32 - Code Injection
CVSS 9.8
CVE-2020-36718
CRITICAL
GDPR CCPA Compliance Support <2.3 - Code Injection
CVSS 9.8
CVE-2020-29312
CRITICAL
Zend Framework < 3.1.3 - Remote Code Execution via Unserialize Function
CVSS 9.8
CVE-2020-10650
HIGH
jackson-databind <2.9.10.4 - Open Redirect
CVSS 8.1
Details
Vulnerabilities
2,841
Exploit Likelihood
Medium