VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 92 of 167
  • CVE-2023-49826HigDec 21, 2023
    risk 0.53cvss 8.1epss 0.01

    Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

  • CVE-2023-4386HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the…

  • CVE-2023-4402HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in…

  • CVE-2022-1415HigSep 11, 2023
    risk 0.53cvss 8.1epss 0.01

    A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

  • CVE-2023-35388HigAug 8, 2023
    risk 0.53cvss 8.0epss 0.07

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-40609HigAug 2, 2023
    risk 0.53cvss 8.1epss 0.02

    IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the…

  • CVE-2023-3001HigJun 14, 2023
    risk 0.53cvss 7.8epss 0.32

    A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.

  • CVE-2023-23836HigFeb 15, 2023
    risk 0.53cvss 7.2epss 0.80

    SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-3360HigOct 31, 2022
    risk 0.53cvss 8.1epss 0.02

    The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this…

  • CVE-2022-22241HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.01

    An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local…

  • CVE-2021-4125HigAug 24, 2022
    risk 0.53cvss 8.1epss 0.01

    It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift…

  • CVE-2022-25863HigJun 10, 2022
    risk 0.53cvss 8.1epss 0.02

    The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this…

  • CVE-2021-42631HigJan 31, 2022
    risk 0.53cvss 8.1epss 0.06

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

  • CVE-2021-41588HigSep 24, 2021
    risk 0.53cvss 8.1epss 0.01

    In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

  • CVE-2021-37678CriAug 12, 2021
    risk 0.53cvss 9.3epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](https://github.com/tensorflow/tensorflow/blo…

  • CVE-2021-37632HigAug 5, 2021
    risk 0.53cvss 8.1epss 0.02

    SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn642's Config Lib between 1.0.4 and 1.0.8 are affected by a vulnerability and can be exploited on both servers and clients. Using SuperMartijn642's Config Lib,…

  • CVE-2021-34520HigJul 14, 2021
    risk 0.53cvss 8.1epss 0.04

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-22439HigJun 29, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability. Successfully exploiting this vulnerability, the attacker can execute remote malicious code injection and to control the device.

  • CVE-2021-33898HigJun 6, 2021
    risk 0.53cvss 8.1epss 0.02

    In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be…

  • CVE-2020-7385HigApr 23, 2021
    risk 0.53cvss 8.1epss 0.02

    By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework…