Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2022-09-06 CVE-2022-2442 Deserialization of Untrusted Data vulnerability in Wpvivid Migration, Backup, Staging
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74.
network
low complexity
wpvivid CWE-502
7.2
2022-09-02 CVE-2022-29063 Deserialization of Untrusted Data vulnerability in Apache Ofbiz
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099.
network
low complexity
apache CWE-502
critical
9.8
2022-08-31 CVE-2022-37021 Deserialization of Untrusted Data vulnerability in Apache Geode
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8.
network
low complexity
apache CWE-502
critical
9.8
2022-08-31 CVE-2022-37022 Deserialization of Untrusted Data vulnerability in Apache Geode
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11.
network
low complexity
apache CWE-502
8.8
2022-08-31 CVE-2022-37023 Deserialization of Untrusted Data vulnerability in Apache Geode
Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11.
network
low complexity
apache CWE-502
6.5
2022-08-25 CVE-2022-36119 Deserialization of Untrusted Data vulnerability in Ssctech Blue Prism
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01.
network
low complexity
ssctech CWE-502
8.8
2022-08-24 CVE-2021-4125 Deserialization of Untrusted Data vulnerability in Redhat Openshift
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.
network
high complexity
redhat CWE-502
8.1
2022-08-24 CVE-2021-4178 Deserialization of Untrusted Data vulnerability in Redhat products
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above.
local
low complexity
redhat CWE-502
6.7
2022-08-22 CVE-2022-33900 Deserialization of Untrusted Data vulnerability in Awesomemotive Easy Digital Downloads
PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
network
low complexity
awesomemotive CWE-502
7.2
2022-08-19 CVE-2022-29805 Deserialization of Untrusted Data vulnerability in Fishbowlinventory Fishbowl
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
network
low complexity
fishbowlinventory CWE-502
critical
9.8