Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2023-11-17 CVE-2023-44351 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution.
network
low complexity
adobe CWE-502
critical
9.8
2023-11-17 CVE-2023-44353 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution.
network
low complexity
adobe CWE-502
critical
9.8
2023-11-14 CVE-2023-47130 Deserialization of Untrusted Data vulnerability in Yiiframework YII
Yii is an open source PHP web framework.
network
low complexity
yiiframework CWE-502
critical
9.8
2023-11-09 CVE-2023-47248 Deserialization of Untrusted Data vulnerability in Apache Pyarrow
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution.
network
low complexity
apache CWE-502
critical
9.8
2023-11-08 CVE-2023-39913 Deserialization of Untrusted Data vulnerability in Apache Uimaj
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. There are several locations in the code where serialized Java objects are deserialized without verifying the data.
network
low complexity
apache CWE-502
8.8
2023-11-03 CVE-2023-46817 Deserialization of Untrusted Data vulnerability in PHPfox
An issue was discovered in phpFox before 4.8.14.
network
low complexity
phpfox CWE-502
critical
9.8
2023-11-02 CVE-2023-47204 Deserialization of Untrusted Data vulnerability in Toumorokoshi Transmute-Core
Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.
network
low complexity
toumorokoshi CWE-502
critical
9.8
2023-11-01 CVE-2023-1714 Deserialization of Untrusted Data vulnerability in Bitrix24 22.0.300
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
network
low complexity
bitrix24 CWE-502
8.8
2023-10-31 CVE-2023-47174 Deserialization of Untrusted Data vulnerability in Thorntech Sftp Gateway Firmware
Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027.
network
low complexity
thorntech CWE-502
critical
9.8
2023-10-30 CVE-2023-45672 Deserialization of Untrusted Data vulnerability in Frigate 0.13.0
Frigate is an open source network video recorder.
network
high complexity
frigate CWE-502
7.5