Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-18903EPSS 5%
Vanilla 2.6.x before 2.6.4 allows remote code execution.
Vanilla
2.6.4+
CRITICAL 9.8
CVE-2018-6012
The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the…
Mini 8 Firmware
after 4.0.975
CRITICAL 9.8
CVE-2018-18892
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
Minicms
No fix yet
HIGH 8.8
CVE-2016-5402EPSS 6%
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…
Cloudforms
Mitigation only
CRITICAL 9.8
CVE-2018-18835
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
Doccms
No fix yet
CRITICAL 9.8
CVE-2018-18461
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via …
Arigato Autoresponder And Newsletter
No fix yet
HIGH 8.8
CVE-2018-18426
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt par…
S Cms
No fix yet
CRITICAL 9.8
CVE-2018-18319EPSS 5%
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has …
Rt Ac5300 Firmware
after 380.70
CRITICAL 9.8
CVE-2018-18258
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via a…
Bagecms
No fix yet
CRITICAL 9.8
CVE-2018-7633
Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a ma…
Epicentro
No fix yet
CRITICAL 9.8
CVE-2018-18083
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during …
Duomicms
No fix yet
CRITICAL 9.8
CVE-2015-9272
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers…
Video Presentation
No fix yet
CRITICAL 9.8
CVE-2018-14804
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
Ams Device Manager
after 13.5
HIGH 7.2
CVE-2018-17827
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into …
Hisiphp
No fix yet
HIGH 8.1
CVE-2018-17364
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
Otcms
No fix yet
CRITICAL 9.8
CVE-2018-17173EPSS 56%
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
Supersign Cms
No fix yet
CRITICAL 9.8
CVE-2018-17207EPSS 60%
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an at…
Duplicator
1.2.42+
HIGH 8.8
CVE-2018-14630
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When imp…
Moodle
3.1.14 / 3.3.8+
CRITICAL 9.8
CVE-2018-11780EPSS 11%
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Spamassassin
3.4.2+
HIGH 7.8
CVE-2018-11781
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Spamassassin
3.4.2+
HIGH 7.2
CVE-2018-17131
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
Phpmywind
No fix yet
HIGH 7.2
CVE-2018-17132
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
Phpmywind
No fix yet
HIGH 7.2
CVE-2018-17133
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
Phpmywind
No fix yet
HIGH 7.2
CVE-2018-17134
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath…
Phpmywind
No fix yet
CRITICAL 9.8
CVE-2018-17126
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
Cscms
No fix yet
CRITICAL 9.8
CVE-2018-17036
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, …
Ucms
No fix yet
HIGH 7.5
CVE-2018-17030
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/f…
Bigtree Cms
No fix yet
CRITICAL 9.8
CVE-2018-16975
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php exte…
Elefant
2.0.7+
MEDIUM 6.7
CVE-2018-3686
Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary cod…
Sa 00086 Detection Tool
1.2.7.0+
HIGH 7.2
CVE-2018-15886
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filenam…
Monstra
No fix yet