CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 35 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36978 | Cri | 0.64 | 9.8 | 0.07 | Mar 29, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists… | ||
| CVE-2022-36977 | Cri | 0.64 | 9.8 | 0.07 | Mar 29, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists… | ||
| CVE-2023-28667 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2023 | The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result… | ||
| CVE-2023-26779 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE). | ||
| CVE-2022-37936 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Unauthenticated Java deserialization vulnerability in Serviceguard Manager | ||
| CVE-2023-26326 | Cri | 0.64 | 9.8 | 0.04 | Feb 23, 2023 | The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects… | ||
| CVE-2023-21707 | Hig | 0.64 | 8.8 | 0.82 | Feb 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-45982 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload. | ||
| CVE-2023-24162 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2023 | Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter. | ||
| CVE-2022-46478 | Cri | 0.64 | 9.8 | 0.01 | Jan 13, 2023 | The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data. | ||
| CVE-2022-41778 | Cri | 0.64 | 9.8 | 0.01 | Jan 13, 2023 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon… | ||
| CVE-2021-32824 | Cri | 0.64 | 9.8 | 0.03 | Jan 3, 2023 | Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers… | ||
| CVE-2021-38241 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework. | ||
| CVE-2022-44351 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2022 | Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php. | ||
| CVE-2022-44371 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2022 | hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). | ||
| CVE-2022-46366 | Cri | 0.64 | 9.8 | 0.04 | Dec 2, 2022 | Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version… | ||
| CVE-2022-45136 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2022 | Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of… | ||
| CVE-2022-45378 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2022 | In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even… | ||
| CVE-2022-38652 | Cri | 0.64 | 9.9 | 0.01 | Nov 12, 2022 | A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of… | ||
| CVE-2022-44562 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. |
- risk 0.64cvss 9.8epss 0.07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…
- risk 0.64cvss 9.8epss 0.07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…
- risk 0.64cvss 9.8epss 0.01
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result…
- risk 0.64cvss 9.8epss 0.01
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
- risk 0.64cvss 9.8epss 0.04
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects…
- risk 0.64cvss 8.8epss 0.82
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
- risk 0.64cvss 9.8epss 0.01
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon…
- risk 0.64cvss 9.8epss 0.03
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers…
- risk 0.64cvss 9.8epss 0.01
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
- risk 0.64cvss 9.8epss 0.01
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
- risk 0.64cvss 9.8epss 0.01
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
- risk 0.64cvss 9.8epss 0.04
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version…
- risk 0.64cvss 9.8epss 0.02
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of…
- risk 0.64cvss 9.8epss 0.02
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…
- risk 0.64cvss 9.9epss 0.01
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of…
- risk 0.64cvss 9.8epss 0.01
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.