Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2021-27475 Deserialization of Untrusted Data vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized.
local
low complexity
rockwellautomation CWE-502
8.6
2022-03-17 CVE-2022-26503 Deserialization of Untrusted Data vulnerability in Veeam
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.
local
low complexity
veeam CWE-502
7.8
2022-03-17 CVE-2022-0749 Deserialization of Untrusted Data vulnerability in Singoo Singoocms.Utility
This affects all versions of package SinGooCMS.Utility.
network
low complexity
singoo CWE-502
critical
9.8
2022-03-10 CVE-2022-23940 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution.
network
low complexity
salesagility CWE-502
8.8
2022-02-18 CVE-2022-0138 Deserialization of Untrusted Data vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be created.
network
low complexity
airspan CWE-502
7.5
2022-02-11 CVE-2021-46364 Deserialization of Untrusted Data vulnerability in Magnolia-Cms Magnolia CMS
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.
local
low complexity
magnolia-cms CWE-502
7.8
2022-02-11 CVE-2022-24289 Deserialization of Untrusted Data vulnerability in Apache Cayenne
Hessian serialization is a network protocol that supports object-based transmission.
network
low complexity
apache CWE-502
8.8
2022-02-09 CVE-2022-0538 Deserialization of Untrusted Data vulnerability in Jenkins
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
network
low complexity
jenkins CWE-502
7.5
2022-01-31 CVE-2021-42631 Deserialization of Untrusted Data vulnerability in Printerlogic Virtual Appliance and web Stack
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
network
high complexity
printerlogic CWE-502
8.1
2022-01-28 CVE-2021-45899 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
network
low complexity
salesagility CWE-502
critical
9.8