VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 33 of 166
  • CVE-2024-35515CriSep 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.

  • CVE-2024-22399CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.03

    Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on…

  • CVE-2023-37227CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

  • CVE-2024-44902CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.04

    A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

  • CVE-2024-37288CriSep 9, 2024
    risk 0.64cvss 9.9epss 0.01

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-fo…

  • CVE-2024-8255CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.

  • CVE-2024-43931CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

  • CVE-2024-8030CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in…

  • CVE-2024-5335CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_compare_products…

  • CVE-2024-43354CriAug 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

  • CVE-2024-43141CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.

  • CVE-2024-6794CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and…

  • CVE-2024-6793CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and…

  • CVE-2024-5488CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.04

    The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is…

  • CVE-2024-5871CriJun 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to…

  • CVE-2024-5671CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.

  • CVE-2024-26289CriMay 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.

  • CVE-2024-4413CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in…

  • CVE-2024-3070CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP…

  • CVE-2024-29212CriMay 14, 2024
    risk 0.64cvss 9.9epss 0.02

    Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.