CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic...Show more |
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via a...Show more |
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. |
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. |
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. |
Unauthenticated PHP Object Injection in Agora <= 1.9 versions. |
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. |
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. |
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. |
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. |
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. |
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. |
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. |
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. |
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. |
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. |
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destinati...Show more |
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path...Show more |
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only s...Show more |