Vulnerabilities (CVE)

Filtered by CWE-502
Total 1768 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-49147 1 Microsoft 1 Update Catalog 2025-01-10 N/A 9.3 CRITICAL
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
CVE-2024-13288 2025-01-10 N/A 4.3 MEDIUM
Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.
CVE-2023-27531 2025-01-09 N/A 5.3 MEDIUM
There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code
CVE-2025-22510 2025-01-09 N/A 7.2 HIGH
Deserialization of Untrusted Data vulnerability in Konrad Karpieszuk WC Price History for Omnibus allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through 2.1.4.
CVE-2024-55556 2025-01-08 N/A 9.8 CRITICAL
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies on an attacker obtaining Laravel's secret APP_KEY, which would allow them to decrypt and manipulate session cookies (laravel_session) containing serialized data. By altering this data and re-encrypting it with the APP_KEY, the attacker could trigger arbitrary deserialization on the server, potentially leading to remote command execution (RCE). The vulnerability is primarily exploited by accessing an exposed cookie and manipulating it using the secret key to gain malicious access to the server.
CVE-2024-3018 1 Wpdeveloper 1 Essential Addons For Elementor 2025-01-08 N/A 8.8 HIGH
The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CVE-2024-30042 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-01-08 N/A 7.8 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-23328 1 Dataease 1 Dataease 2025-01-08 N/A 9.1 CRITICAL
Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.
CVE-2024-30044 1 Microsoft 1 Sharepoint Server 2025-01-08 N/A 7.2 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-1731 1 Rymera 1 Auto Refresh Single Page 2025-01-08 N/A 8.8 HIGH
The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CVE-2024-49070 1 Microsoft 1 Sharepoint Server 2025-01-08 N/A 7.4 HIGH
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2024-49063 1 Microsoft 1 Muzic 2025-01-08 N/A 8.4 HIGH
Microsoft/Muzic Remote Code Execution Vulnerability
CVE-2024-55555 2025-01-07 N/A 8.8 HIGH
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client.php file can be accessed without authentication. The parameter {hash} is passed to the function decrypt that expects a Laravel ciphered value containing a serialized object. (Furthermore, Laravel contains several gadget chains usable to trigger remote command execution from arbitrary deserialization.) Therefore, an attacker in possession of the APP_KEY is able to fully control a string passed to an unserialize function.
CVE-2023-33496 1 Xxl-rpc Project 1 Xxl-rpc 2025-01-07 N/A 9.8 CRITICAL
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
CVE-2023-33284 1 Marvalglobal 1 Msm 2025-01-07 N/A 8.8 HIGH
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.
CVE-2023-20888 1 Vmware 1 Vrealize Network Insight 2025-01-07 N/A 8.8 HIGH
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
CVE-2024-10012 1 Telerik 1 Ui For Wpf 2025-01-07 N/A 7.8 HIGH
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
CVE-2024-10013 1 Telerik 1 Ui For Winforms 2025-01-07 N/A 7.8 HIGH
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
CVE-2024-56291 2025-01-07 N/A 8.1 HIGH
Deserialization of Untrusted Data vulnerability in plainware.com PlainInventory allows Object Injection.This issue affects PlainInventory: from n/a through 3.1.6.
CVE-2024-56283 2025-01-07 N/A 8.1 HIGH
Deserialization of Untrusted Data vulnerability in plainware.com Locatoraid Store Locator allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through 3.9.50.