VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 119 of 166
  • CVE-2023-32736HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC…

  • CVE-2024-49684HigOct 23, 2024
    risk 0.47cvss 7.2epss 0.01

    Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.

  • CVE-2024-9005HigOct 8, 2024
    risk 0.47cvss —epss 0.00

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.

  • CVE-2024-43191HigSep 26, 2024
    risk 0.47cvss 7.2epss 0.01

    IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

  • CVE-2024-7351HigAug 24, 2024
    risk 0.47cvss 7.2epss 0.01

    The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and…

  • CVE-2024-7560HigAug 8, 2024
    risk 0.47cvss 7.2epss 0.01

    The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and…

  • CVE-2024-2290HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP…

  • CVE-2023-4971HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2023-26153HigOct 6, 2023
    risk 0.47cvss 8.3epss 0.03

    Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to…

  • CVE-2023-20878HigMay 12, 2023
    risk 0.47cvss 7.2epss 0.01

    VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.

  • CVE-2022-47507HigFeb 15, 2023
    risk 0.47cvss 7.2epss 0.07

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2023-21710HigFeb 14, 2023
    risk 0.47cvss 7.2epss 0.08

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-3380HigOct 31, 2022
    risk 0.47cvss 7.2epss 0.01

    The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2022-3374HigOct 31, 2022
    risk 0.47cvss 7.2epss 0.01

    The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the…

  • CVE-2022-3366HigOct 31, 2022
    risk 0.47cvss 7.2epss 0.01

    The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations.…

  • CVE-2022-3334HigOct 31, 2022
    risk 0.47cvss 7.2epss 0.01

    The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2022-3335HigOct 25, 2022
    risk 0.47cvss 7.2epss 0.01

    The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2022-2903HigSep 26, 2022
    risk 0.47cvss 7.2epss 0.01

    The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2022-2442HigSep 6, 2022
    risk 0.47cvss 7.2epss 0.02

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files…

  • CVE-2022-25845HigJun 10, 2022
    risk 0.47cvss 8.1epss 0.19

    The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If…