CWE-502
3,223 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,223)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP reques...Show more |
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malici...Show more |
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects...Show more |
Unauthenticated PHP Object Injection in Moderno < 1.43 versions. |
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. |
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. |
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. |
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. |
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. |
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. |
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. |
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. |
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. |
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. |
Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Busi...Show more |
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. |
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. |
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection.
This issue affects Creatify: from n/a through 1.5. |
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection.
This issue affects The Hospital: from n/a through 1.8.1. |
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection.
This issue affects The Barber Shop: from n/a through 1.9. |