VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 100 of 156
  • CVE-2024-5726HigJul 18, 2024
    risk 0.50cvss 8.8epss 0.01

    The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted input 'timelines-data' parameter. This makes it possible for authenticated attackers, with Contributor-level access…

  • CVE-2023-46801HigJul 15, 2024
    risk 0.50cvss 8.8epss 0.01

    In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the server and execute…

  • CVE-2024-38024HigJul 9, 2024
    risk 0.50cvss 7.2epss 0.45

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-4200HigMay 15, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

  • CVE-2024-34515HigMay 5, 2024
    risk 0.50cvss 8.8epss 0.02

    image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().

  • CVE-2024-3054HigApr 12, 2024
    risk 0.50cvss 7.2epss 0.42

    WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient…

  • CVE-2024-2693HigApr 9, 2024
    risk 0.50cvss 8.8epss 0.01

    The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level…

  • CVE-2024-3018HigMar 30, 2024
    risk 0.50cvss 8.8epss 0.01

    The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default).…

  • CVE-2024-1770HigMar 28, 2024
    risk 0.50cvss 8.8epss 0.01

    The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.2 via deserialization of untrusted input in the get_post_data function. This makes it possible for authenticated attackers, with contributor access or…

  • CVE-2024-2025HigMar 23, 2024
    risk 0.50cvss 8.8epss 0.01

    The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untrusted input in the get_simple_request function. This makes it…

  • CVE-2024-1801HigMar 20, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

  • CVE-2024-22284HigJan 24, 2024
    risk 0.50cvss 8.7epss 0.01

    Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

  • CVE-2023-52206HigJan 8, 2024
    risk 0.50cvss 7.7epss 0.01

    Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

  • CVE-2023-6730HigDec 19, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

  • CVE-2023-39913HigNov 8, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommended to upgrade to version 3.5.0, which…

  • CVE-2023-40195HigAug 28, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to…

  • CVE-2023-3343HigJul 13, 2023
    risk 0.50cvss 8.8epss 0.01

    The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above,…

  • CVE-2023-27296HigMar 27, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 through 1.5.0. …

  • CVE-2022-3568HigFeb 10, 2023
    risk 0.50cvss 8.8epss 0.01

    The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site…

  • CVE-2022-3525HigNov 20, 2022
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.