CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,842 vulnerabilities with CWE-502
CVE-2020-2211
HIGH
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin <1.3 - RCE
CVSS 8.8
CVE-2020-10740
MEDIUM
Wildfly <20.0.0.Final - Deserialization
CVSS 6.6
CVE-2020-14942
CRITICAL
Tendenci < 12.0.11 - Deserialization of Untrusted Data in Helpdesk Staff Views
CVSS 9.8
CVE-2020-14933
HIGH
SquirrelMail 1.4.22 - Info Disclosure
CVSS 8.8
CVE-2020-14932
CRITICAL
SquirrelMail <1.4.22 - Code Injection
CVSS 9.8
CVE-2020-8165
CRITICAL
Rails <5.2.4.3-6.0.3.1 - Deserialization
CVSS 9.8
CVE-2020-8164
HIGH
Rails <5.2.4.3-6.0.3.1 - Info Disclosure
CVSS 7.5
CVE-2020-14195
HIGH
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via org.jsecurity.realm.jndi.JndiRealmFactory
CVSS 8.1
CVE-2020-14060
HIGH
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via apache/drill JNDIConnectionPool
CVSS 8.1
CVE-2020-14062
HIGH
FasterXML jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via xalan2 JNDIConnectionPool
CVSS 8.1
CVE-2020-14061
HIGH
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via Oracle AQjms Gadgets
CVSS 8.1
CVE-2020-5411
HIGH
Spring Batch 4.0.0-4.0.3 and 4.1.0-4.2.2 - Remote Code Execution via Jackson Default Typing
CVSS 8.1
CVE-2020-0132
MEDIUM
Android 10 - Local Information Disclosure via Unsafe Deserialization in BnAAudioService
CVSS 5.5
CVE-2020-4043
HIGH
phpMussel 1.0.0-1.5.9 - Remote Code Execution via PHAR Deserialization
CVSS 7.7
CVE-2020-12000
HIGH
Ignition Gateway < 7.9.14 - Deserialization of Untrusted Data
CVSS 7.5
CVE-2020-10644
HIGH
Ignition <8.0.10, <7.9.14 - Info Disclosure
CVSS 7.5
CVE-2020-4450
CRITICAL
IBM WebSphere Application Server 8.5.0.0-8.5.5.17 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
CVE-2020-4449
HIGH
IBM WebSphere Application Server 7.0.0.0-7.0.0.45 - Information Disclosure via Deserialization of Untrusted Data
CVSS 7.5
CVE-2020-4448
CRITICAL
IBM WebSphere Application Server 7.0-9.0 - Remote Code Execution via Untrusted Object Deserialization
CVSS 9.8
CVE-2020-7660
HIGH
serialize-javascript < 3.1.0 - Remote Code Execution via deleteFunctions
CVSS 8.1
CVE-2020-12390
CRITICAL
Firefox < 76.0 - Incorrect Origin Serialization via IPv6 URL Handling
CVSS 9.8
CVE-2020-3280
CRITICAL
Cisco Unified Contact Center Express 12.0-12.0(1)es03 - RCE via Insecure Java Deserialization
CVSS 9.8
CVE-2020-9484
HIGH
Apache Tomcat < 7.0.108 - Insecure Deserialization
CVSS 7.0
CVE-2020-12835
CRITICAL
SmartBear ReadyAPI SoapUI Pro 3.2.5 - Code Injection
CVSS 9.8
CVE-2020-13092
CRITICAL
scikit-learn <0.23.0 - Command Injection
CVSS 9.8
Details
Vulnerabilities
2,842
Exploit Likelihood
Medium