Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-18889EPSS 33%
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces …
Symfony
after 4.3.7
CRITICAL 9.8
CVE-2019-5509
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully e…
Ontap Select Deploy Administration Utility
after 2.12.2
CRITICAL 9.8
CVE-2019-19010
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose i…
Fedora
2019.11.09+
HIGH 8.1
CVE-2019-15388
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-ins…
Mega 5 Firmware
Mitigation only
CRITICAL 9.8
CVE-2013-1666
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
Foswiki
1.1.8+
CRITICAL 10.0
CVE-2018-4031
An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsin…
Smart Firewall
Mitigation only
CRITICAL 9.8
CVE-2019-10211
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di…
PostgreSQL
9.4.24 / 9.5.19+
CRITICAL 9.8
CVE-2019-17526
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web app…
Sagemathcell
Patch available
CRITICAL 9.8
CVE-2019-17613
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply …
Qibosoft
No fix yet
CRITICAL 9.8
CVE-2019-17408
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be…
Zzzphp
No fix yet
MEDIUM 5.3
CVE-2019-3652
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their mali…
Endpoint Security
10.6.1+
HIGH 8.8
CVE-2018-21023
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
Centreon Web
2.8.28 / 18.10.5+
HIGH 7.2
CVE-2019-17299
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17300
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17301
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17302
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17303
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17304
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17305
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17306
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17307
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17308
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17309
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17310
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
CRITICAL 9.8
CVE-2019-15746
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute sy…
Sitos Six
Mitigation only
CRITICAL 9.8
CVE-2019-17132EPSS 12%
vBulletin through 5.5.4 mishandles custom avatars.
Vbulletin
after 5.5.4
CRITICAL 9.9
CVE-2019-10431
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constru…
Script Security
after 1.64
CRITICAL 9.8
CVE-2019-16759 KEVEPSS 100%
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Vbulletin
after 5.5.4
HIGH 8.6
CVE-2019-16645EPSS 8%
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostna…
Goahead
No fix yet
HIGH 7.2
CVE-2019-15087
An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote …
Adas
Patch available