Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Logontracer CRITICAL 9.8
CVE-2018-16168

LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.

Fix: after 1.2.0
Fix from $2,300 2019-01-09
Chrome HIGH 8.8
CVE-2016-9651EPSS 11%

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute ar…

Fix: 55.0.2883.75+
Fix from $1,950 2019-01-09
Openshift Container Platform HIGH 8.8
CVE-2019-0542

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi…

Fix: 3.9.99 / 3.10.163+
Fix from $1,950 2019-01-09
Cloud Connector CRITICAL 9.8
CVE-2019-0247

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby cont…

Fix: 2.11.3+
Fix from $2,300 2019-01-08
Sqla Yaml Fixtures HIGH 7.8
CVE-2019-3575

Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.

No fix yet
Fix from $1,950 2019-01-03
Ucms HIGH 8.8
CVE-2018-20599

UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.

No fix yet
Fix from $1,950 2018-12-30
Imcat CRITICAL 9.8
CVE-2018-20605

imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.

No fix yet
Fix from $2,300 2018-12-30
Evlink Parking Firmware HIGH 8.8
CVE-2018-7801EPSS 6%

A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote co…

Fix: after 3.2.0-12
Fix from $1,950 2018-12-24
Definitions CRITICAL 9.8
CVE-2018-20325

There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary pyt…

No fix yet
Fix from $2,300 2018-12-21
Server CRITICAL 9.8
CVE-2018-1000881

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in Computed…

Fix: after 4.0
Fix from $2,300 2018-12-20
Empirecms CRITICAL 9.8
CVE-2018-20300

Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is i…

No fix yet
Fix from $2,300 2018-12-20
Ymlref CRITICAL 9.8
CVE-2018-20133

ymlref allows code injection.

No fix yet
Fix from $2,300 2018-12-17
Pylearn2 CRITICAL 9.8
CVE-2018-20027

The yaml_parse.load method in Pylearn2 allows code injection.

No fix yet
Fix from $2,300 2018-12-17
Icinga Web 2 CRITICAL 9.8
CVE-2018-18249

Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information …

Fix: 2.6.2+
Fix from $2,300 2018-12-17
Dedecms HIGH 8.8
CVE-2018-20129EPSS 8%

An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PH…

No fix yet
Fix from $1,950 2018-12-13
.net Framework CRITICAL 9.8
CVE-2018-8540EPSS 22%

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Inje…

Patch available
Fix from $2,300 2018-12-12
Pbootcms CRITICAL 9.8
CVE-2018-19595

PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php…

No fix yet
Fix from $2,300 2018-11-27
PHP HIGH 8.8
CVE-2018-19520

An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain …

Fix: after 5.6.38
Fix from $1,950 2018-11-25
Z Blogphp HIGH 8.8
CVE-2018-19463

zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content ty…

Fix: after 1.5.1
Fix from $1,950 2018-11-22
Yxcms HIGH 7.2
CVE-2018-19404

In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating…

No fix yet
Fix from $1,950 2018-11-21
Powershell Core HIGH 7.8
CVE-2018-8415

A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerabili…

Patch available
Fix from $1,950 2018-11-14
Fiori Client HIGH 7.8
CVE-2018-2491

When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL cont…

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Websphere Mq HIGH 7.8
CVE-2018-1792

IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that cou…

Fix: after 9.0.5
Fix from $1,950 2018-11-13
Websphere Commerce HIGH 8.8
CVE-2018-1808

IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.

Fix: after 9.0.0.6
Fix from $1,950 2018-11-13
Laobancms CRITICAL 9.8
CVE-2018-19220

An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.

No fix yet
Fix from $2,300 2018-11-12
Xiaocms CRITICAL 9.8
CVE-2018-19196

An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard …

No fix yet
Fix from $2,300 2018-11-12
Yunucms CRITICAL 9.8
CVE-2018-19180

statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by p…

No fix yet
Fix from $2,300 2018-11-11
Phpcms CRITICAL 9.8
CVE-2018-19127EPSS 21%

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable fi…

Mitigation only
Fix from $2,300 2018-11-09
Pbootcms HIGH 7.2
CVE-2018-19053

PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, foll…

No fix yet
Fix from $1,950 2018-11-07
Richfaces CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…

Fix: after 3.3.4
Fix from $2,300 2018-11-06