Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-8132
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based …
Pdf Image
after 2.0.0
CRITICAL 9.8
CVE-2020-9406
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
Online Weather
4.3.5+
HIGH 7.8
CVE-2019-4000
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to exe…
Insync
No fix yet
CRITICAL 9.8
CVE-2020-8518EPSS 72%
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Fedora
No fix yet
CRITICAL 9.8
CVE-2020-8129
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
Script Manager
after 0.8.6
CRITICAL 9.8
CVE-2013-4211EPSS 71%
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malici…
Openx
No fix yet
HIGH 8.8
CVE-2013-4225
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity wri…
Restful Web Services
7.x-1.4 / 7.x-2.1+
HIGH 8.1
CVE-2020-5529
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can …
Debian Linux
2.37.0+
CRITICAL 9.8
CVE-2019-17268
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions …
Omniauth Weibo Oauth2
Patch available
CRITICAL 9.8
CVE-2020-8644 KEVEPSS 87%
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
Playsms
1.4.3+
HIGH 7.2
CVE-2013-2267EPSS 9%
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
Fudforum
Mitigation only
CRITICAL 9.8
CVE-2020-6836
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanit…
Hot Formula Parser
3.0.1+
CRITICAL 9.8
CVE-2019-20343
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin elem…
Exec Maven
Mitigation only
HIGH 8.8
CVE-2019-20155
An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may exe…
Contract Lifecycle Management
No fix yet
CRITICAL 9.9
CVE-2019-10758 KEVEPSS 85%
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to pe…
Mongo Express
0.54.0+
HIGH 8.8
CVE-2019-19909
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injectio…
Open Journal System
3.1.2-2+
HIGH 8.8
CVE-2019-7486
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA10…
Sma 100 Firmware
after 9.0.0.4
CRITICAL 9.8
CVE-2019-15597
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Node Df
Mitigation only
CRITICAL 9.8
CVE-2019-15598
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Treekill
Mitigation only
CRITICAL 9.8
CVE-2019-15599
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Tree Kill
Mitigation only
CRITICAL 9.8
CVE-2019-4716 KEVEPSS 86%
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th…
Planning Analytics
after 2.0.8
CRITICAL 9.8
CVE-2019-16774
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
Phpfastcache
5.0.13+
CRITICAL 9.8
CVE-2019-10769
safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to A…
Safer Eval
No fix yet
CRITICAL 9.8
CVE-2019-16885
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. Thi…
Okaycms
after 2.3.4
MEDIUM 6.5
CVE-2019-3665
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the br…
Webadvisor
4.1.1.48+
CRITICAL 9.8
CVE-2019-19502
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP…
Image Uploader And Browser For Ckeditor
4.1.9+
HIGH 8.8
CVE-2019-14867EPSS 7%
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the interna…
Fedora
4.6.7 / 4.7.4+
HIGH 8.1
CVE-2019-16255
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[]…
Ruby
after 2.6.4
MEDIUM 6.1
CVE-2019-13714
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS…
Chrome
78.0.3904.70+
HIGH 7.2
CVE-2019-3427
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inj…
Zxcdn Iamweb Firmware
Mitigation only