Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-16168
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
Logontracer
after 1.2.0
HIGH 8.8
CVE-2016-9651EPSS 11%
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute ar…
Chrome
55.0.2883.75+
HIGH 8.8
CVE-2019-0542
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi…
Openshift Container Platform
3.9.99 / 3.10.163+
CRITICAL 9.8
CVE-2019-0247
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby cont…
Cloud Connector
2.11.3+
HIGH 7.8
CVE-2019-3575
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
Sqla Yaml Fixtures
No fix yet
HIGH 8.8
CVE-2018-20599
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
Ucms
No fix yet
CRITICAL 9.8
CVE-2018-20605
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
Imcat
No fix yet
HIGH 8.8
CVE-2018-7801EPSS 6%
A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote co…
Evlink Parking Firmware
after 3.2.0-12
CRITICAL 9.8
CVE-2018-20325
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary pyt…
Definitions
No fix yet
CRITICAL 9.8
CVE-2018-1000881
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in Computed…
Server
after 4.0
CRITICAL 9.8
CVE-2018-20300
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is i…
Empirecms
No fix yet
CRITICAL 9.8
CVE-2018-20133
ymlref allows code injection.
Ymlref
No fix yet
CRITICAL 9.8
CVE-2018-20027
The yaml_parse.load method in Pylearn2 allows code injection.
Pylearn2
No fix yet
CRITICAL 9.8
CVE-2018-18249
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information …
Icinga Web 2
2.6.2+
HIGH 8.8
CVE-2018-20129EPSS 8%
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PH…
Dedecms
No fix yet
CRITICAL 9.8
CVE-2018-8540EPSS 22%
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Inje…
.net Framework
Patch available
CRITICAL 9.8
CVE-2018-19595
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php…
Pbootcms
No fix yet
HIGH 8.8
CVE-2018-19520
An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain …
PHP
after 5.6.38
HIGH 8.8
CVE-2018-19463
zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content ty…
Z Blogphp
after 1.5.1
HIGH 7.2
CVE-2018-19404
In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating…
Yxcms
No fix yet
HIGH 7.8
CVE-2018-8415
A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerabili…
Powershell Core
Patch available
HIGH 7.8
CVE-2018-2491
When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL cont…
Fiori Client
1.11.5+
HIGH 7.8
CVE-2018-1792
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that cou…
Websphere Mq
after 9.0.5
HIGH 8.8
CVE-2018-1808
IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.
Websphere Commerce
after 9.0.0.6
CRITICAL 9.8
CVE-2018-19220
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
Laobancms
No fix yet
CRITICAL 9.8
CVE-2018-19196
An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard …
Xiaocms
No fix yet
CRITICAL 9.8
CVE-2018-19180
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by p…
Yunucms
No fix yet
CRITICAL 9.8
CVE-2018-19127EPSS 21%
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable fi…
Phpcms
Mitigation only
HIGH 7.2
CVE-2018-19053
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, foll…
Pbootcms
No fix yet
CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…
Richfaces
after 3.3.4