Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-6143EPSS 6%
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in ins…
Opensis
No fix yet
CRITICAL 9.8
CVE-2020-6144EPSS 6%
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in ins…
Opensis
No fix yet
CRITICAL 9.8
CVE-2020-15150
There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to …
Paginator
1.0.0+
HIGH 8.5
CVE-2020-15147
Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users wit…
Red Discord Bot
after 3.3.11
CRITICAL 9.8
CVE-2020-7710
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
Safe Eval
No fix yet
HIGH 8.8
CVE-2020-15070
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write…
Zulip Server
2.1.7+
CRITICAL 9.8
CVE-2020-15865EPSS 5%
A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the …
Reports
No fix yet
CRITICAL 9.0
CVE-2020-15142
In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subs…
Openapi Python Client
0.5.3+
CRITICAL 9.8
CVE-2020-10055EPSS 6%
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications …
Desigo Consumption Control
Patch available
HIGH 7.8
CVE-2020-8224
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
Desktop
2.6.5+
HIGH 7.2
CVE-2020-8218 KEVEPSS 32%
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution …
Connect Secure
after 9.0
HIGH 7.5
CVE-2020-7694
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever an…
Uvicorn
No fix yet
CRITICAL 9.1
CVE-2020-12013
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi El…
Mc Works32
after 10.95.208.31
CRITICAL 9.8
CVE-2020-11546EPSS 33%
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticat…
Superwebmailer
7.40.0.01550+
MEDIUM 6.5
CVE-2020-8194EPSS 11%
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD…
Application Delivery Controller Firmware
10.2.7 / 10.5-70.18+
HIGH 8.8
CVE-2020-8163EPSS 82%
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `rend…
Rails
5.0.1+
CRITICAL 9.8
CVE-2020-15348
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c…
Cloud Cnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2016-11064
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
Mattermost Desktop
3.4.0+
HIGH 8.8
CVE-2020-5593
Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.
Zenphoto
1.5.7+
HIGH 8.6
CVE-2020-7672
mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, result…
Mosc
after 1.0.0
CRITICAL 9.8
CVE-2020-7673
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` l…
Node Extend
after 0.2.0
CRITICAL 9.8
CVE-2020-7674
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` funct…
Access Policy
after 3.1.0
CRITICAL 9.8
CVE-2020-7675
cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function re…
Cd Messenger
after 2.7.26
CRITICAL 9.9
CVE-2020-8180
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an adminis…
Talk
6.0.5 / 7.0.3+
HIGH 8.8
CVE-2020-7012EPSS 18%
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privile…
Kibana
after 7.6.2
HIGH 7.2
CVE-2020-7013
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualiza…
Kibana
6.8.9 / 7.7.0+
CRITICAL 9.8
CVE-2020-13756EPSS 55%
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or g…
Php Css Parser
8.3.1+
CRITICAL 9.8
CVE-2020-11079
node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client o…
Node Dns Sync
0.2.1+
CRITICAL 9.8
CVE-2019-5997
Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.
Video Insight Vms
after 7.5
HIGH 8.8
CVE-2020-13144EPSS 11%
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new…
Open Edx Platform
No fix yet