VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 11 of 167
  • CVE-2023-52218CriJan 8, 2024
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.

  • CVE-2023-52181CriDec 31, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

  • CVE-2023-51505CriDec 29, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a…

  • CVE-2023-49778CriDec 21, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

  • CVE-2023-49773CriDec 20, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Tim Brattberg BCorp Shortcodes.This issue affects BCorp Shortcodes: from n/a through 0.23.

  • CVE-2023-49772CriDec 20, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a through 2.0.

  • CVE-2023-47207CriNov 30, 2023
    risk 0.65cvss 9.8epss 0.17

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

  • CVE-2022-41875CriNov 23, 2022
    risk 0.65cvss 10.0epss 0.02

    A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked system running Optica. The vulnerability…

  • CVE-2022-38650CriNov 12, 2022
    risk 0.65cvss 10.0epss 0.01

    A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the…

  • CVE-2022-38142CriOct 31, 2022
    risk 0.65cvss 9.8epss 0.18

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon…

  • CVE-2022-38352CriSep 15, 2022
    risk 0.65cvss 9.8epss 0.21

    ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2022-33107CriJun 29, 2022
    risk 0.65cvss 9.8epss 0.24

    ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2022-1660CriJun 2, 2022
    risk 0.65cvss 9.8epss 0.17

    The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-27470CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27466CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27462CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27460CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain…

  • CVE-2021-43297CriJan 10, 2022
    risk 0.65cvss 9.8epss 0.17

    A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian…

  • CVE-2019-19810CriOct 28, 2021
    risk 0.65cvss 10.0epss 0.05

    Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.

  • CVE-2021-37181CriSep 14, 2021
    risk 0.65cvss 10.0epss 0.02

    A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC…