Vulnerabilities (CVE)

Filtered by CWE-502
Total 1324 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27158 1 Php 1 Pearweb 2022-04-22 7.5 HIGH 9.8 CRITICAL
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
CVE-2021-21956 1 Cloudlinux 1 Imunify360 2022-04-21 9.3 HIGH 7.8 HIGH
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2019-6834 1 Schneider-electric 1 Software Update 2022-04-20 9.3 HIGH 7.8 HIGH
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)
CVE-2022-23450 1 Siemens 2 Simatic Energy Manager Basic, Simatic Energy Manager Pro 2022-04-19 10.0 HIGH 9.8 CRITICAL
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.
CVE-2021-3287 1 Zohocorp 1 Manageengine Opmanager 2022-04-18 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
CVE-2019-15780 1 Strategy11 1 Formidable Form Builder 2022-04-18 7.5 HIGH 9.8 CRITICAL
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
CVE-2020-4272 2 Ibm, Linux 2 Qradar Security Information And Event Manager, Linux Kernel 2022-04-18 6.5 MEDIUM 8.8 HIGH
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-ForceID: 175898.
CVE-2020-4271 2 Ibm, Linux 2 Qradar Security Information And Event Manager, Linux Kernel 2022-04-18 6.5 MEDIUM 6.3 MEDIUM
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.
CVE-2020-19229 1 Jeesite 1 Jeesite 2022-04-13 7.5 HIGH 9.8 CRITICAL
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.
CVE-2021-33207 1 Softwareag 1 Mashzone Nextgen 2022-04-13 7.5 HIGH 9.8 CRITICAL
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
CVE-2022-1032 1 Craterapp 1 Crater 2022-04-04 6.5 MEDIUM 7.2 HIGH
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
CVE-2021-27470 1 Rockwellautomation 1 Factorytalk Assetcentre 2022-03-29 7.5 HIGH 9.8 CRITICAL
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
CVE-2021-27466 1 Rockwellautomation 1 Factorytalk Assetcentre 2022-03-29 7.5 HIGH 9.8 CRITICAL
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
CVE-2021-27462 1 Rockwellautomation 1 Factorytalk Assetcentre 2022-03-29 7.5 HIGH 9.8 CRITICAL
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
CVE-2021-27475 1 Rockwellautomation 1 Connected Components Workbench 2022-03-29 6.8 MEDIUM 8.6 HIGH
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.
CVE-2021-27460 1 Rockwellautomation 1 Factorytalk Assetcentre 2022-03-29 7.5 HIGH 9.8 CRITICAL
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk AssetCentre main server and all agent machines.
CVE-2021-46364 1 Magnolia-cms 1 Magnolia Cms 2022-03-29 6.8 MEDIUM 7.8 HIGH
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.
CVE-2022-0749 1 Singoo 1 Singoocms.utility 2022-03-24 7.5 HIGH 9.8 CRITICAL
This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.
CVE-2022-26503 2 Microsoft, Veeam 2 Windows, Veeam 2022-03-23 7.2 HIGH 7.8 HIGH
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.
CVE-2022-21828 1 Ivanti 1 Incapptic Connect 2022-03-21 6.5 MEDIUM 7.2 HIGH
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.