CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,841 vulnerabilities with CWE-502
CVE-2021-22855 CRITICAL
HR Portal - Remote Code Execution via Untrusted Deserialization
CVSS 9.8
CVE-2021-23338 MEDIUM
qlib < 0.7.0 - Remote Code Execution via Unsafe YAML Deserialization
CVSS 6.6
CVE-2021-27213 CRITICAL
pystemon < 2021-02-13 - Remote Code Execution via YAML Deserialization
CVSS 9.8
CVE-2021-26915 HIGH
NetMotion Mobility < 11.73 & 12.x < 12.02 - RCE via Java Deserialization in StatusServlet
CVSS 8.1
CVE-2021-26914 HIGH
NetMotion Mobility < 11.73 and 12.x < 12.02 - Unauthenticated Remote Code Execution via Java Deserialization in MvcUtil
CVSS 8.1
CVE-2021-26913 HIGH
NetMotion Mobility < 11.73 and 12.x < 12.02 - Remote Code Execution via Java Deserialization
CVSS 8.1
CVE-2021-26912 HIGH
NetMotion Mobility <11.73/12.x<12.02 - RCE via Java Deserialization
CVSS 8.1
CVE-2021-25274 CRITICAL
SolarWinds Orion Platform <2020.2.4 - RCE
CVSS 9.8
CVE-2021-25758 HIGH
JetBrains IntelliJ IDEA < 2020.3 - Local Code Execution via Insecure Workspace Model Deserialization
CVSS 7.8
CVE-2021-3160 CRITICAL
ACA ASSUREX RENTES ASSUWEB 359.3 build 1 - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2021-20190 HIGH
jackson-databind < 2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
CVE-2021-25294 CRITICAL
OpenCATS <= 0.9.5-3 - Remote Code Execution via Unsafe Deserialization in DataGrid Activity Parameter
CVSS 9.8
CVE-2021-21249 CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via SnakeYAML Deserialization
CVSS 9.6
CVE-2021-21247 CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via AJAX Event Listener Deserialization
CVSS 9.6
CVE-2021-21242 CRITICAL
OneDev < 4.0.3 - Unauthenticated Remote Code Execution via Attachment-Support Header Deserialization
CVSS 10.0
CVE-2021-21243 CRITICAL
OneDev <4.0.3 - Pre-Auth Code Injection
CVSS 10.0
CVE-2021-21604 HIGH
Jenkins < 2.263.1, < 2.274 - Deserialization of Untrusted Data via Old Data Monitor
CVSS 8.0
CVE-2021-3007 CRITICAL
Laminas Project laminas-http <2.14.2 - Code Injection
CVSS 9.8
CVE-2020-37071 CRITICAL
CraftCMS 3 vCard Plugin 1.0.0 - Code Injection
CVSS 9.8
CVE-2020-19559 CRITICAL
Diebold Aglis XFS for Opteva 4.1.61.1 - Remote Code Execution via ResolveMethod() Parameter
CVSS 9.8
CVE-2020-36727 CRITICAL
Newsletter Manager <1.5.1 - Open Redirect
CVSS 9.8
CVE-2020-36726 CRITICAL
Ultimate Reviews <2.1.32 - Code Injection
CVSS 9.8
CVE-2020-36718 CRITICAL
GDPR CCPA Compliance Support <2.3 - Code Injection
CVSS 9.8
CVE-2020-29312 CRITICAL
Zend Framework < 3.1.3 - Remote Code Execution via Unserialize Function
CVSS 9.8
CVE-2020-10650 HIGH
jackson-databind <2.9.10.4 - Open Redirect
CVSS 8.1
Details
Vulnerabilities 2,841
Exploit Likelihood Medium