CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 30 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48206 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2024 | A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code. | ||
| CVE-2024-48063 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2024 | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing. | ||
| CVE-2024-49625 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2024 | Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0. | ||
| CVE-2024-49624 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2024 | Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1. | ||
| CVE-2024-49332 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2024 | Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4. | ||
| CVE-2024-49626 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2024 | Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.This issue affects Shipyaari Shipping Management: from n/a through <= 1.2. | ||
| CVE-2024-49318 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2024 | Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0. | ||
| CVE-2024-49227 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4. | ||
| CVE-2024-49218 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1. | ||
| CVE-2024-48030 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2. | ||
| CVE-2024-48028 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1. | ||
| CVE-2024-48026 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0. | ||
| CVE-2024-48033 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2024 | Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0. | ||
| CVE-2024-47636 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2024 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9. | ||
| CVE-2024-35515 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2024 | Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code. | ||
| CVE-2024-22399 | Cri | 0.64 | 9.8 | 0.03 | Sep 16, 2024 | Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on… | ||
| CVE-2023-37227 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. | ||
| CVE-2024-44902 | Cri | 0.64 | 9.8 | 0.04 | Sep 9, 2024 | A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | ||
| CVE-2024-37288 | Cri | 0.64 | 9.9 | 0.01 | Sep 9, 2024 | A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-fo… | ||
| CVE-2024-8255 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability. |
- risk 0.64cvss 9.8epss 0.01
A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.
- risk 0.64cvss 9.8epss 0.02
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.This issue affects Shipyaari Shipping Management: from n/a through <= 1.2.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.
- risk 0.64cvss 9.8epss 0.01
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on…
- risk 0.64cvss 9.8epss 0.01
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
- risk 0.64cvss 9.8epss 0.04
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.9epss 0.01
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-fo…
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.