Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Hoosk CRITICAL 9.8
CVE-2018-16771

Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php.

No fix yet
Fix from $2,300 2018-09-10
Nibbleblog HIGH 7.2
CVE-2018-16604

An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the usern…

No fix yet
Fix from $1,950 2018-09-06
Attachecase HIGH 7.8
CVE-2018-0675

AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.

Fix: after 3.3.0.0
Fix from $1,950 2018-09-04
Attachecase HIGH 7.8
CVE-2018-0674

AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.

Fix: after 2.8.4.0
Fix from $1,950 2018-09-04
Seacms HIGH 7.2
CVE-2018-16343

SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.

No fix yet
Fix from $1,950 2018-09-02
Data Center Automation CRITICAL 9.8
CVE-2018-6498

Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…

Mitigation only
Fix from $2,300 2018-08-30
Data Center Automation CRITICAL 9.8
CVE-2018-6499

Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…

Mitigation only
Fix from $2,300 2018-08-30
Mod Perl CRITICAL 9.8
CVE-2011-2767EPSS 9%

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…

Fix: after 2.0.10
Fix from $2,300 2018-08-26
Couchbase Server HIGH 8.8
CVE-2018-15728

Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Ad…

No fix yet
Fix from $1,950 2018-08-24
Phpwhois CRITICAL 9.8
CVE-2015-5243EPSS 6%

phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.

Fix: after 4.2.2
Fix from $2,300 2018-08-20
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1753

Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec…

Fix: after 6.0.5
Fix from $1,600 2018-08-20
Cryo CRITICAL 9.8
CVE-2018-3784

A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.

No fix yet
Fix from $2,300 2018-08-17
Windows 10 HIGH 8.8
CVE-2018-8344EPSS 22%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…

Mitigation only
Fix from $1,950 2018-08-15
Windows 10 HIGH 7.5
CVE-2018-8345EPSS 14%

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote…

Mitigation only
Fix from $1,950 2018-08-15
Seomatic HIGH 7.5
CVE-2018-14716EPSS 33%

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any eleme…

Fix: 3.1.4+
Fix from $1,950 2018-08-06
Arcsight Winc Connector CRITICAL 9.8
CVE-2016-4391EPSS 20%

A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.

Fix: 7.3.0+
Fix from $2,300 2018-08-06
Network Node Manager I HIGH 7.8
CVE-2016-4397

A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.

No fix yet
Fix from $1,950 2018-08-06
Seacms HIGH 8.8
CVE-2018-14910

SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The…

No fix yet
Fix from $1,950 2018-08-03
Servicenow HIGH 8.8
CVE-2018-7748

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…

No fix yet
Fix from $1,950 2018-08-03
Golemcms CRITICAL 9.8
CVE-2018-14579

GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by…

Fix: after 2008-12-24
Fix from $2,300 2018-07-24
Html Quickform CRITICAL 9.8
CVE-2018-1999022

PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's vali…

Fix: after 4.6.37
Fix from $2,300 2018-07-23
The Battle For Wesnoth HIGH 8.8
CVE-2018-1999023

The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in co…

Fix: after 1.14.3
Fix from $1,950 2018-07-23
Chamilo Lms CRITICAL 9.8
CVE-2018-1999019

Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.ph…

Patch available
Fix from $2,300 2018-07-23
Seacms HIGH 8.8
CVE-2018-14421

SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admi…

Mitigation only
Fix from $1,950 2018-07-20
Webedition Cms CRITICAL 9.8
CVE-2014-2302

The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by i…

Fix: 6.2.7.0 / 6.3.8+
Fix from $2,300 2018-07-19
Drupal CRITICAL 9.8
CVE-2018-7602 KEVEPSS 99%

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple …

Fix: 7.59 / 8.4.8+
Fix from $2,300 2018-07-19
Phpcms CRITICAL 9.8
CVE-2018-14399

libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SR…

Mitigation only
Fix from $2,300 2018-07-19
.net Framework HIGH 8.1
CVE-2018-8284EPSS 39%

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Inje…

Patch available
Fix from $1,950 2018-07-11
Businessobjects Business Intelligence HIGH 8.8
CVE-2018-2427

SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allow…

Patch available
Fix from $1,950 2018-07-10
Twig CRITICAL 9.8
CVE-2018-13818EPSS 7%

Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is n…

Fix: 2.4.4+
Fix from $2,300 2018-07-10