Vulnerabilities > Deserialization of Untrusted Data
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-19 | CVE-2022-1984 | Deserialization of Untrusted Data vulnerability in Hypr Workforce Access This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload. | 7.8 |
2022-07-19 | CVE-2022-24082 | Deserialization of Untrusted Data vulnerability in Pega Infinity If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. | 9.8 |
2022-07-19 | CVE-2022-35405 | Deserialization of Untrusted Data vulnerability in Zohocorp products Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. | 9.8 |
2022-07-18 | CVE-2022-2437 | Deserialization of Untrusted Data vulnerability in Slickremix Feed Them Social The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. | 9.8 |
2022-07-18 | CVE-2022-2444 | Deserialization of Untrusted Data vulnerability in Themeisle Visualizer The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, and including 3.7.9. | 8.8 |
2022-07-18 | CVE-2021-41419 | Deserialization of Untrusted Data vulnerability in Qvis DVR Firmware and NVR Firmware QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. | 9.8 |
2022-07-17 | CVE-2022-30981 | Deserialization of Untrusted Data vulnerability in Gentics CMS 5.43.0 An issue was discovered in Gentics CMS before 5.43.1. | 8.8 |
2022-07-12 | CVE-2021-36665 | Deserialization of Untrusted Data vulnerability in Druva Insync Client An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon. | 7.8 |
2022-06-29 | CVE-2022-33107 | Deserialization of Untrusted Data vulnerability in Thinkphp 6.0.12 ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. | 9.8 |
2022-06-15 | CVE-2022-20195 | Deserialization of Untrusted Data vulnerability in Google Android 12.1 In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. | 5.0 |