Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Vanilla CRITICAL 9.8
CVE-2018-18903EPSS 5%

Vanilla 2.6.x before 2.6.4 allows remote code execution.

Fix: 2.6.4+
Fix from $2,300 2018-11-03
Mini 8 Firmware CRITICAL 9.8
CVE-2018-6012

The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the…

Fix: after 4.0.975
Fix from $2,300 2018-11-01
Minicms CRITICAL 9.8
CVE-2018-18892

MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.

No fix yet
Fix from $2,300 2018-11-01
Cloudforms HIGH 8.8
CVE-2016-5402EPSS 6%

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…

Mitigation only
Fix from $1,950 2018-10-31
Doccms CRITICAL 9.8
CVE-2018-18835

upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.

No fix yet
Fix from $2,300 2018-10-30
Arigato Autoresponder And Newsletter CRITICAL 9.8
CVE-2018-18461

The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via …

No fix yet
Fix from $2,300 2018-10-18
S Cms HIGH 8.8
CVE-2018-18426

s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt par…

No fix yet
Fix from $1,950 2018-10-17
Rt Ac5300 Firmware CRITICAL 9.8
CVE-2018-18319EPSS 5%

An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has …

Fix: after 380.70
Fix from $2,300 2018-10-15
Bagecms CRITICAL 9.8
CVE-2018-18258

An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via a…

No fix yet
Fix from $2,300 2018-10-11
Epicentro CRITICAL 9.8
CVE-2018-7633

Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a ma…

No fix yet
Fix from $2,300 2018-10-09
Duomicms CRITICAL 9.8
CVE-2018-18083

An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during …

No fix yet
Fix from $2,300 2018-10-09
Video Presentation CRITICAL 9.8
CVE-2015-9272

The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers…

No fix yet
Fix from $2,300 2018-10-05
Ams Device Manager CRITICAL 9.8
CVE-2018-14804

Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.

Fix: after 13.5
Fix from $2,300 2018-10-01
Hisiphp HIGH 7.2
CVE-2018-17827

HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into …

No fix yet
Fix from $1,950 2018-10-01
Otcms HIGH 8.1
CVE-2018-17364

OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.

No fix yet
Fix from $1,950 2018-09-23
Supersign Cms CRITICAL 9.8
CVE-2018-17173EPSS 56%

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

No fix yet
Fix from $2,300 2018-09-21
Duplicator CRITICAL 9.8
CVE-2018-17207EPSS 60%

An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an at…

Fix: 1.2.42+
Fix from $2,300 2018-09-19
Moodle HIGH 8.8
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When imp…

Fix: 3.1.14 / 3.3.8+
Fix from $1,950 2018-09-17
Spamassassin CRITICAL 9.8
CVE-2018-11780EPSS 11%

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

Fix: 3.4.2+
Fix from $2,300 2018-09-17
Spamassassin HIGH 7.8
CVE-2018-11781

Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

Fix: 3.4.2+
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17131

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.

No fix yet
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17132

admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.

No fix yet
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17133

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.

No fix yet
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17134

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath…

No fix yet
Fix from $1,950 2018-09-17
Cscms CRITICAL 9.8
CVE-2018-17126

CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.

No fix yet
Fix from $2,300 2018-09-17
Ucms CRITICAL 9.8
CVE-2018-17036

An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, …

No fix yet
Fix from $2,300 2018-09-14
Bigtree Cms HIGH 7.5
CVE-2018-17030

BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/f…

No fix yet
Fix from $1,950 2018-09-14
Elefant CRITICAL 9.8
CVE-2018-16975

An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php exte…

Fix: 2.0.7+
Fix from $2,300 2018-09-12
Sa 00086 Detection Tool MEDIUM 6.7
CVE-2018-3686

Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary cod…

Fix: 1.2.7.0+
Fix from $1,600 2018-09-12
Monstra HIGH 7.2
CVE-2018-15886

Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filenam…

No fix yet
Fix from $1,950 2018-09-10