Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Ansible Tower HIGH 8.8
CVE-2018-1104

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…

Fix: after 3.2.3
Fix from $1,950 2018-05-02
Itop HIGH 7.2
CVE-2018-10642EPSS 7%

Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platfo…

Fix: after 2.4.1
Fix from $1,950 2018-05-02
Whatsup Gold CRITICAL 9.8
CVE-2018-8938

A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…

Fix: 18.0+
Fix from $2,300 2018-05-01
Bigtree Cms CRITICAL 9.8
CVE-2018-10574

site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeSto…

Fix: after 4.2.22
Fix from $2,300 2018-04-30
Cms Made Simple HIGH 7.2
CVE-2018-10515

In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitab…

Fix: after 2.2.7
Fix from $1,950 2018-04-27
Cms Made Simple HIGH 7.2
CVE-2018-10517EPSS 12%

In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploi…

Fix: after 2.2.7
Fix from $1,950 2018-04-27
Cosmo CRITICAL 9.8
CVE-2018-10429

Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.

No fix yet
Fix from $2,300 2018-04-26
Qradar Security Information And Event Manager MEDIUM 5.6
CVE-2017-1721

IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumsta…

Fix: 7.2.8+
Fix from $1,600 2018-04-26
Microbetrace HIGH 7.8
CVE-2018-8974

Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, related to code injection via a cra…

Patch available
Fix from $1,950 2018-04-26
Microbetrace HIGH 7.8
CVE-2018-9113

Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 allows remote attackers to execute arbitrary code, related to code injection via a cra…

Patch available
Fix from $1,950 2018-04-26
Poscms HIGH 7.2
CVE-2018-10235

POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because …

No fix yet
Fix from $1,950 2018-04-19
Poscms HIGH 7.2
CVE-2018-10236

POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an …

No fix yet
Fix from $1,950 2018-04-19
Pbootcms CRITICAL 9.8
CVE-2018-10133

PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel functi…

No fix yet
Fix from $2,300 2018-04-16
Cms Made Simple HIGH 7.2
CVE-2018-10086

CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval…

Fix: after 2.2.7
Fix from $1,950 2018-04-13
Excel Services HIGH 8.8
CVE-2018-1028EPSS 19%

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft O…

Patch available
Fix from $1,950 2018-04-12
Spring Data Rest CRITICAL 9.8
CVE-2018-1273 KEVEPSS 96%

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused …

Fix: after 3.0.5
Fix from $2,300 2018-04-11
Spring Framework CRITICAL 9.8
CVE-2018-1275EPSS 58%

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP ove…

Fix: 4.3.16 / 5.0.5+
Fix from $2,300 2018-04-11
Gxlcms Qy CRITICAL 9.8
CVE-2018-9847

In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by plac…

No fix yet
Fix from $2,300 2018-04-07
Gxlcms Qy CRITICAL 9.8
CVE-2018-9848

In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by f…

No fix yet
Fix from $2,300 2018-04-07
Spring Framework CRITICAL 9.8
CVE-2018-1270EPSS 77%

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP ove…

Fix: 4.3.16 / 5.0.5+
Fix from $2,300 2018-04-06
Network Security Manager MEDIUM 6.1
CVE-2017-3967

Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers…

Fix: 8.2.7.42.2+
Fix from $1,600 2018-04-04
Dedecms CRITICAL 9.8
CVE-2018-9174

sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modify…

Mitigation only
Fix from $2,300 2018-04-02
Dedecms CRITICAL 9.8
CVE-2018-9175

DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within th…

Mitigation only
Fix from $2,300 2018-04-02
Responsive Mega Menu Pro CRITICAL 9.8
CVE-2018-8823EPSS 51%

modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2…

Fix: after 1.7.2.5
Fix from $2,300 2018-03-28
Zikula Application Framework CRITICAL 9.8
CVE-2014-2293

Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or exec…

Fix: after 1.3.6
Fix from $2,300 2018-03-26
Zzcms HIGH 7.5
CVE-2018-8966

An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a php…

No fix yet
Fix from $1,950 2018-03-24
Emc Idrac7 CRITICAL 9.8
CVE-2018-1207EPSS 90%

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauth…

Fix: 2.52.52.52+
Fix from $2,300 2018-03-23
Tivoli Monitoring CRITICAL 9.8
CVE-2017-1789

IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 13…

Mitigation only
Fix from $2,300 2018-03-22
Yii CRITICAL 9.8
CVE-2018-8073

Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis e…

Fix: 2.0.15+
Fix from $2,300 2018-03-21
Yii HIGH 8.1
CVE-2018-8074

Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with th…

Fix: 2.0.15+
Fix from $1,950 2018-03-21