Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,960 CVEs tagged with CWE-5021,130 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2019-6340

Published Feb 21, 2019

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in…

CVSS 8.1 · High
evidence mentions
13
Buzz score
64.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7743

Published Feb 12, 2019

An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1000005

Published Feb 4, 2019

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry co…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6503

Published Jan 22, 2019

There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6338

Published Jan 22, 2019

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a se…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6446

Published Jan 16, 2019

An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20718

Published Jan 15, 2019

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6331

Published Dec 31, 2018

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000833

Published Dec 20, 2018

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remot…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000832

Published Dec 20, 2018

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remot…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000827

Published Dec 20, 2018

Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000824

Published Dec 20, 2018

MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20148

Published Dec 14, 2018

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1904

Published Dec 11, 2018

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 2,726-2,750 of 2,960 CVEsPage 110 of 119