CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. |
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions. |
Unauthenticated PHP Object Injection in Valiance <= 1.2 versions. |
Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions. |
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions. |
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions. |
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions. |
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions. |
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions. |
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. |
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. |
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. |
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. |
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. |
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions. |
Contributor PHP Object Injection in Avada <= 3.15.3 versions. |
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . Th...Show more |
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel....Show more |
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. |
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. |