Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2021-01-04 CVE-2021-3007 Deserialization of Untrusted Data vulnerability in multiple products
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php.
network
low complexity
getlaminas zend CWE-502
critical
9.8
2021-01-01 CVE-2020-35939 Deserialization of Untrusted Data vulnerability in Pickplugins Post Grid and Team Showcase
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX.
network
low complexity
pickplugins CWE-502
8.8
2021-01-01 CVE-2020-35938 Deserialization of Untrusted Data vulnerability in Pickplugins Post Grid and Team Showcase
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX.
network
low complexity
pickplugins CWE-502
8.8
2021-01-01 CVE-2020-35932 Deserialization of Untrusted Data vulnerability in Tribulant Newsletter
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter.
network
low complexity
tribulant CWE-502
8.8
2020-12-31 CVE-2020-26165 Deserialization of Untrusted Data vulnerability in Qdpm 8.3/9.0/9.1
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
network
low complexity
qdpm CWE-502
8.8
2020-12-31 CVE-2019-7725 Deserialization of Untrusted Data vulnerability in Nukeviet
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
network
low complexity
nukeviet CWE-502
critical
9.8
2020-12-27 CVE-2020-35728 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
network
high complexity
fasterxml debian netapp oracle CWE-502
8.1
2020-12-17 CVE-2020-35491 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
network
high complexity
fasterxml netapp debian oracle CWE-502
8.1
2020-12-17 CVE-2020-35490 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
network
high complexity
fasterxml netapp debian oracle CWE-502
8.1
2020-12-17 CVE-2020-22083 Deserialization of Untrusted Data vulnerability in Jsonpickle Project Jsonpickle
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function.
network
low complexity
jsonpickle-project CWE-502
critical
9.8