Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2024-09-28 CVE-2024-8353 Deserialization of Untrusted Data vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'.
network
low complexity
givewp CWE-502
critical
9.8
2024-09-27 CVE-2024-8922 Deserialization of Untrusted Data vulnerability in Piwebsolution Product Enquiry for Woocommerce
The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untrusted input in enquiry_detail.php.
network
low complexity
piwebsolution CWE-502
8.8
2024-09-26 CVE-2024-43191 IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.
network
low complexity
CWE-502
7.2
2024-09-25 CVE-2024-7576 Deserialization of Untrusted Data vulnerability in Telerik UI for WPF
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
network
low complexity
telerik CWE-502
critical
9.8
2024-09-25 CVE-2024-8316 Deserialization of Untrusted Data vulnerability in Telerik UI for WPF
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
local
low complexity
telerik CWE-502
7.8
2024-09-25 CVE-2024-8514 Deserialization of Untrusted Data vulnerability in Prisna Google Website Translator
The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter.
network
low complexity
prisna CWE-502
7.2
2024-09-16 CVE-2024-22399 Deserialization of Untrusted Data vulnerability in Apache Seata
Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protocol. This issue affects Apache Seata: 2.0.0, from 1.0.0 through 1.8.0. Users are recommended to upgrade to version 2.1.0/1.8.1, which fixes the issue.
network
low complexity
apache CWE-502
critical
9.8
2024-09-14 CVE-2024-8862 Deserialization of Untrusted Data vulnerability in H2O 3.46.0.4
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4.
network
low complexity
h2o CWE-502
critical
9.8
2024-09-13 CVE-2022-2446 Deserialization of Untrusted Data vulnerability in Benjaminrojas WP Editor
The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9.
network
low complexity
benjaminrojas CWE-502
7.2
2024-09-13 CVE-2024-41874 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion 2021/2023
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user.
network
low complexity
adobe CWE-502
critical
9.8