Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2018-16168 LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors. Logontracer after 1.2.0 Fix from $2,3002019-01-09 HIGH 8.8 CVE-2016-9651EPSS 11% A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute ar… Chrome 55.0.2883.75+ Fix from $1,9502019-01-09 HIGH 8.8 CVE-2019-0542 A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi… Openshift Container Platform 3.9.99 / 3.10.163+ Fix from $1,9502019-01-09 CRITICAL 9.8 CVE-2019-0247 SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby cont… Cloud Connector 2.11.3+ Fix from $2,3002019-01-08 HIGH 7.8 CVE-2019-3575 Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load. Sqla Yaml Fixtures No fix yet Fix from $1,9502019-01-03 HIGH 8.8 CVE-2018-20599 UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. Ucms No fix yet Fix from $1,9502018-12-30 CRITICAL 9.8 CVE-2018-20605 imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file. Imcat No fix yet Fix from $2,3002018-12-30 HIGH 8.8 CVE-2018-7801EPSS 6% A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote co… Evlink Parking Firmware after 3.2.0-12 Fix from $1,9502018-12-24 CRITICAL 9.8 CVE-2018-20325 There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary pyt… Definitions No fix yet Fix from $2,3002018-12-21 CRITICAL 9.8 CVE-2018-1000881 Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in Computed… Server after 4.0 Fix from $2,3002018-12-20 CRITICAL 9.8 CVE-2018-20300 Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is i… Empirecms No fix yet Fix from $2,3002018-12-20 CRITICAL 9.8 CVE-2018-20133 ymlref allows code injection. Ymlref No fix yet Fix from $2,3002018-12-17 CRITICAL 9.8 CVE-2018-20027 The yaml_parse.load method in Pylearn2 allows code injection. Pylearn2 No fix yet Fix from $2,3002018-12-17 CRITICAL 9.8 CVE-2018-18249 Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information … Icinga Web 2 2.6.2+ Fix from $2,3002018-12-17 HIGH 8.8 CVE-2018-20129EPSS 8% An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PH… Dedecms No fix yet Fix from $1,9502018-12-13 CRITICAL 9.8 CVE-2018-8540EPSS 22% A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Inje… .net Framework Patch available Fix from $2,3002018-12-12 CRITICAL 9.8 CVE-2018-19595 PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php… Pbootcms No fix yet Fix from $2,3002018-11-27 HIGH 8.8 CVE-2018-19520 An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain … PHP after 5.6.38 Fix from $1,9502018-11-25 HIGH 8.8 CVE-2018-19463 zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content ty… Z Blogphp after 1.5.1 Fix from $1,9502018-11-22 HIGH 7.2 CVE-2018-19404 In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating… Yxcms No fix yet Fix from $1,9502018-11-21 HIGH 7.8 CVE-2018-8415 A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerabili… Powershell Core Patch available Fix from $1,9502018-11-14 HIGH 7.8 CVE-2018-2491 When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL cont… Fiori Client 1.11.5+ Fix from $1,9502018-11-13 HIGH 7.8 CVE-2018-1792 IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that cou… Websphere Mq after 9.0.5 Fix from $1,9502018-11-13 HIGH 8.8 CVE-2018-1808 IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828. Websphere Commerce after 9.0.0.6 Fix from $1,9502018-11-13 CRITICAL 9.8 CVE-2018-19220 An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI. Laobancms No fix yet Fix from $2,3002018-11-12 CRITICAL 9.8 CVE-2018-19196 An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard … Xiaocms No fix yet Fix from $2,3002018-11-12 CRITICAL 9.8 CVE-2018-19180 statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by p… Yunucms No fix yet Fix from $2,3002018-11-11 CRITICAL 9.8 CVE-2018-19127EPSS 21% A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable fi… Phpcms Mitigation only Fix from $2,3002018-11-09 HIGH 7.2 CVE-2018-19053 PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, foll… Pbootcms No fix yet Fix from $1,9502018-11-07 CRITICAL 9.8 CVE-2018-14667 KEVEPSS 74% The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate… Richfaces after 3.3.4 Fix from $2,3002018-11-06