Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2017-18108
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute…
Crowd
2.10.2+
CRITICAL 9.8
CVE-2018-19641
Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior t…
Solutions Business Manager
11.5+
CRITICAL 9.8
CVE-2014-5401EPSS 5%
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthent…
Mednet
after 5.8
CRITICAL 10.0
CVE-2019-7609 KEVEPSS 95%
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion …
Kibana
5.6.15 / 6.6.1+
CRITICAL 9.0
CVE-2019-7610
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi…
Kibana
5.6.15 / 6.6.1+
HIGH 7.2
CVE-2019-10015
baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this co…
Baigo Sso
Mitigation only
CRITICAL 9.8
CVE-2019-5413
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
Morgan
1.9.1+
CRITICAL 9.8
CVE-2019-9651
An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, res…
Sdcms
No fix yet
HIGH 8.1
CVE-2013-7468
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
Simple Machines Forum
No fix yet
CRITICAL 9.8
CVE-2019-9227
An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter…
Baigo Cms
No fix yet
CRITICAL 9.8
CVE-2019-9115
In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage.
Irisnet Crypto
1.1.7+
HIGH 8.8
CVE-2019-9082 KEVEPSS 97%
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefu…
Thinkphp
3.2.4+
MEDIUM 6.7
CVE-2018-3700
Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windows 7 before version 5.0.4.43v…
Usb 3.0 Extensible Host Controller Driver
5.0.4.43v2+
CRITICAL 9.8
CVE-2019-8341EPSS 45%
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parame…
Jinja2
No fix yet
CRITICAL 9.8
CVE-2019-7719
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
Nibbleblog
No fix yet
CRITICAL 9.8
CVE-2019-7720
taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
Taocms
after 2014-05-24
HIGH 7.2
CVE-2018-20775
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file …
Frog Cms
No fix yet
HIGH 7.2
CVE-2018-20772
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
Frog Cms
No fix yet
HIGH 7.2
CVE-2018-20773
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
Frog Cms
No fix yet
CRITICAL 9.8
CVE-2018-20768
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…
Workcentre 3655i Firmware
073.060.048.15000 / 073.190.048.15000+
CRITICAL 9.8
CVE-2019-7692
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file misha…
Cim
No fix yet
HIGH 8.8
CVE-2019-7580EPSS 10%
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mish…
Thinkcmf
No fix yet
HIGH 7.8
CVE-2018-19002
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may …
Laquis Scada
4.1.0.4150+
MEDIUM 6.2
CVE-2019-4038
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypass…
Security Identity Manager
after 7.0.1.10
CRITICAL 9.8
CVE-2019-6713
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving port…
Thinkcmf
Mitigation only
HIGH 8.8
CVE-2018-19011
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code u…
Cx Supervisor
after 3.42
HIGH 8.8
CVE-2017-18356
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account th…
Woocommerce
3.2.4+
HIGH 8.8
CVE-2018-20717
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of …
Prestashop
1.7.2.5+
MEDIUM 6.1
CVE-2017-1002152
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
Bodhi
after 2.9.0
HIGH 8.8
CVE-2018-0461
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection a…
Ip Phone 8800 Series Firmware
Mitigation only