Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-16771
Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php.
Hoosk
No fix yet
HIGH 7.2
CVE-2018-16604
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the usern…
Nibbleblog
No fix yet
HIGH 7.8
CVE-2018-0675
AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
Attachecase
after 3.3.0.0
HIGH 7.8
CVE-2018-0674
AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.
Attachecase
after 2.8.4.0
HIGH 7.2
CVE-2018-16343
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
Seacms
No fix yet
CRITICAL 9.8
CVE-2018-6498
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…
Data Center Automation
Mitigation only
CRITICAL 9.8
CVE-2018-6499
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…
Data Center Automation
Mitigation only
CRITICAL 9.8
CVE-2011-2767EPSS 9%
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…
Mod Perl
after 2.0.10
HIGH 8.8
CVE-2018-15728
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Ad…
Couchbase Server
No fix yet
CRITICAL 9.8
CVE-2015-5243EPSS 6%
phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.
Phpwhois
after 4.2.2
MEDIUM 5.4
CVE-2017-1753
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec…
Rational Doors Next Generation
after 6.0.5
CRITICAL 9.8
CVE-2018-3784
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Cryo
No fix yet
HIGH 8.8
CVE-2018-8344EPSS 22%
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…
Windows 10
Mitigation only
HIGH 7.5
CVE-2018-8345EPSS 14%
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote…
Windows 10
Mitigation only
HIGH 7.5
CVE-2018-14716EPSS 33%
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any eleme…
Seomatic
3.1.4+
CRITICAL 9.8
CVE-2016-4391EPSS 20%
A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.
Arcsight Winc Connector
7.3.0+
HIGH 7.8
CVE-2016-4397
A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.
Network Node Manager I
No fix yet
HIGH 8.8
CVE-2018-14910
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The…
Seacms
No fix yet
HIGH 8.8
CVE-2018-7748
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…
Servicenow
No fix yet
CRITICAL 9.8
CVE-2018-14579
GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by…
Golemcms
after 2008-12-24
CRITICAL 9.8
CVE-2018-1999022
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's vali…
Html Quickform
after 4.6.37
HIGH 8.8
CVE-2018-1999023
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in co…
The Battle For Wesnoth
after 1.14.3
CRITICAL 9.8
CVE-2018-1999019
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.ph…
Chamilo Lms
Patch available
HIGH 8.8
CVE-2018-14421
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admi…
Seacms
Mitigation only
CRITICAL 9.8
CVE-2014-2302
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by i…
Webedition Cms
6.2.7.0 / 6.3.8+
CRITICAL 9.8
CVE-2018-7602 KEVEPSS 99%
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple …
Drupal
7.59 / 8.4.8+
CRITICAL 9.8
CVE-2018-14399
libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SR…
Phpcms
Mitigation only
HIGH 8.1
CVE-2018-8284EPSS 39%
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Inje…
.net Framework
Patch available
HIGH 8.8
CVE-2018-2427
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allow…
Businessobjects Business Intelligence
Patch available
CRITICAL 9.8
CVE-2018-13818EPSS 7%
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is n…
Twig
2.4.4+