VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 32 of 156
  • CVE-2024-29433CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

  • CVE-2024-30228CriMar 28, 2024
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.

  • CVE-2024-24725HigMar 23, 2024
    risk 0.64cvss 8.8epss 0.51

    Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

  • CVE-2024-28212CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

  • CVE-2024-28211CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.

  • CVE-2024-24302CriMar 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the postProcess() method.

  • CVE-2024-23052CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.05

    An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

  • CVE-2023-51518CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in privilege escalation. Note…

  • CVE-2024-24797CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.

  • CVE-2023-6049CriJan 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

  • CVE-2023-52219CriJan 8, 2024
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

  • CVE-2023-52182CriDec 31, 2023
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

  • CVE-2023-51470CriDec 29, 2023
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

  • CVE-2023-51422CriDec 29, 2023
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom…

  • CVE-2022-34268CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

  • CVE-2023-32242CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.

  • CVE-2023-51656CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.

  • CVE-2023-46279CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

  • CVE-2023-29234CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.07

    A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

  • CVE-2023-48967CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.