Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2018-18903EPSS 5% Vanilla 2.6.x before 2.6.4 allows remote code execution. Vanilla 2.6.4+ Fix from $2,3002018-11-03 CRITICAL 9.8 CVE-2018-6012 The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the… Mini 8 Firmware after 4.0.975 Fix from $2,3002018-11-01 CRITICAL 9.8 CVE-2018-18892 MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. Minicms No fix yet Fix from $2,3002018-11-01 HIGH 8.8 CVE-2016-5402EPSS 6% A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces… Cloudforms Mitigation only Fix from $1,9502018-10-31 CRITICAL 9.8 CVE-2018-18835 upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file. Doccms No fix yet Fix from $2,3002018-10-30 CRITICAL 9.8 CVE-2018-18461 The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via … Arigato Autoresponder And Newsletter No fix yet Fix from $2,3002018-10-18 HIGH 8.8 CVE-2018-18426 s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt par… S Cms No fix yet Fix from $1,9502018-10-17 CRITICAL 9.8 CVE-2018-18319EPSS 5% An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has … Rt Ac5300 Firmware after 380.70 Fix from $2,3002018-10-15 CRITICAL 9.8 CVE-2018-18258 An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via a… Bagecms No fix yet Fix from $2,3002018-10-11 CRITICAL 9.8 CVE-2018-7633 Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a ma… Epicentro No fix yet Fix from $2,3002018-10-09 CRITICAL 9.8 CVE-2018-18083 An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during … Duomicms No fix yet Fix from $2,3002018-10-09 CRITICAL 9.8 CVE-2015-9272 The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers… Video Presentation No fix yet Fix from $2,3002018-10-05 CRITICAL 9.8 CVE-2018-14804 Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution. Ams Device Manager after 13.5 Fix from $2,3002018-10-01 HIGH 7.2 CVE-2018-17827 HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into … Hisiphp No fix yet Fix from $1,9502018-10-01 HIGH 8.1 CVE-2018-17364 OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. Otcms No fix yet Fix from $1,9502018-09-23 CRITICAL 9.8 CVE-2018-17173EPSS 56% LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. Supersign Cms No fix yet Fix from $2,3002018-09-21 CRITICAL 9.8 CVE-2018-17207EPSS 60% An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an at… Duplicator 1.2.42+ Fix from $2,3002018-09-19 HIGH 8.8 CVE-2018-14630 moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When imp… Moodle 3.1.14 / 3.3.8+ Fix from $1,9502018-09-17 CRITICAL 9.8 CVE-2018-11780EPSS 11% A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. Spamassassin 3.4.2+ Fix from $2,3002018-09-17 HIGH 7.8 CVE-2018-11781 Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. Spamassassin 3.4.2+ Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17131 admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. Phpmywind No fix yet Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17132 admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. Phpmywind No fix yet Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17133 admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. Phpmywind No fix yet Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17134 admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath… Phpmywind No fix yet Fix from $1,9502018-09-17 CRITICAL 9.8 CVE-2018-17126 CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php. Cscms No fix yet Fix from $2,3002018-09-17 CRITICAL 9.8 CVE-2018-17036 An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, … Ucms No fix yet Fix from $2,3002018-09-14 HIGH 7.5 CVE-2018-17030 BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/f… Bigtree Cms No fix yet Fix from $1,9502018-09-14 CRITICAL 9.8 CVE-2018-16975 An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php exte… Elefant 2.0.7+ Fix from $2,3002018-09-12 MEDIUM 6.7 CVE-2018-3686 Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary cod… Sa 00086 Detection Tool 1.2.7.0+ Fix from $1,6002018-09-12 HIGH 7.2 CVE-2018-15886 Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filenam… Monstra No fix yet Fix from $1,9502018-09-10