Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2019-11552
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A p…
Code42 For Enterprise
6.7.5 / 6.8.8+
CRITICAL 9.8
CVE-2019-13956
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5…
Discuz\!ml
after 3.4
CRITICAL 9.8
CVE-2019-9848EPSS 31%
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. …
Ubuntu Linux
6.2.5+
CRITICAL 9.8
CVE-2019-6823
A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker…
Proclima
8.0.0+
CRITICAL 9.1
CVE-2019-0330
The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to …
Diagnostics Agent
Mitigation only
CRITICAL 9.8
CVE-2019-13354
The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current ver…
Strong Password
Mitigation only
CRITICAL 9.8
CVE-2019-13372EPSS 82%
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PH…
Central Wifimanager
after 1.03
MEDIUM 6.1
CVE-2019-12843
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 201…
Teamcity
2018.2.3+
MEDIUM 6.1
CVE-2019-12844
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
Teamcity
2018.2.3+
CRITICAL 9.8
CVE-2019-10100
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an…
Youtrack Integration
1.8.1.3+
HIGH 7.8
CVE-2019-5443
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 au…
Curl
after 8.0.17
MEDIUM 6.3
CVE-2019-1577
Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.
Traps
after 5.0.5
HIGH 8.1
CVE-2018-17170
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend…
Teamwire
1.9.0+
MEDIUM 6.5
CVE-2018-18836
An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/a…
Netdata
Patch available
HIGH 8.8
CVE-2018-18879
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating sys…
Weather Microserver Firmware
Mitigation only
HIGH 8.8
CVE-2019-8324
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacke…
Debian Linux
after 3.0.2
HIGH 7.5
CVE-2019-12761
A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_…
Pyxdg
0.26+
HIGH 8.6
CVE-2017-14853
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct she…
Siteomat
6.4.414.122+
CRITICAL 9.8
CVE-2019-9891
The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands …
Advanced Bash Scripting Guide
No fix yet
CRITICAL 9.1
CVE-2019-6816
In Modicon Quantum all firmware versions, a CWE-94: Code Injection vulnerability could cause an unauthorized firmware modification with possible Deni…
Modicon Quantum Firmware
Mitigation only
HIGH 7.8
CVE-2019-0091
Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may …
Converged Security And Management Engine
3.1.65 / 4.0.15+
HIGH 8.8
CVE-2019-11642
A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can…
Oneshield Policy
5.1.10+
HIGH 8.1
CVE-2019-11593
In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web ser…
Adblock Plus
3.5.2+
HIGH 8.1
CVE-2019-11594
In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service…
Adblock
3.45.0+
HIGH 8.8
CVE-2011-1830
Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
Ekiga
3.3.0+
HIGH 7.2
CVE-2019-11376
SOY CMS v3.0.2 allows remote attackers to execute arbitrary PHP code via a <?php substring in the second text box. NOTE: the vendor indicates that th…
Soy Cms
No fix yet
HIGH 8.8
CVE-2019-10633
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker t…
Nas326 Firmware
after 5.21
HIGH 7.2
CVE-2019-10863EPSS 13%
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wi…
Teemip
2.4.0+
CRITICAL 9.8
CVE-2019-10842
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker…
Bootstrap Sass
No fix yet
CRITICAL 9.8
CVE-2019-10684
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Adm…
74cms
No fix yet