Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2018-16771 Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php. Hoosk No fix yet Fix from $2,3002018-09-10 HIGH 7.2 CVE-2018-16604 An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the usern… Nibbleblog No fix yet Fix from $1,9502018-09-06 HIGH 7.8 CVE-2018-0675 AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors. Attachecase after 3.3.0.0 Fix from $1,9502018-09-04 HIGH 7.8 CVE-2018-0674 AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors. Attachecase after 2.8.4.0 Fix from $1,9502018-09-04 HIGH 7.2 CVE-2018-16343 SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS. Seacms No fix yet Fix from $1,9502018-09-02 CRITICAL 9.8 CVE-2018-6498 Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con… Data Center Automation Mitigation only Fix from $2,3002018-08-30 CRITICAL 9.8 CVE-2018-6499 Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con… Data Center Automation Mitigation only Fix from $2,3002018-08-30 CRITICAL 9.8 CVE-2011-2767EPSS 9% mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do… Mod Perl after 2.0.10 Fix from $2,3002018-08-26 HIGH 8.8 CVE-2018-15728 Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Ad… Couchbase Server No fix yet Fix from $1,9502018-08-24 CRITICAL 9.8 CVE-2015-5243EPSS 6% phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. Phpwhois after 4.2.2 Fix from $2,3002018-08-20 MEDIUM 5.4 CVE-2017-1753 Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec… Rational Doors Next Generation after 6.0.5 Fix from $1,6002018-08-20 CRITICAL 9.8 CVE-2018-3784 A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization. Cryo No fix yet Fix from $2,3002018-08-17 HIGH 8.8 CVE-2018-8344EPSS 22% A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi… Windows 10 Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2018-8345EPSS 14% A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote… Windows 10 Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2018-14716EPSS 33% A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any eleme… Seomatic 3.1.4+ Fix from $1,9502018-08-06 CRITICAL 9.8 CVE-2016-4391EPSS 20% A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0. Arcsight Winc Connector 7.3.0+ Fix from $2,3002018-08-06 HIGH 7.8 CVE-2016-4397 A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software. Network Node Manager I No fix yet Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-14910 SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The… Seacms No fix yet Fix from $1,9502018-08-03 HIGH 8.8 CVE-2018-7748 report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj… Servicenow No fix yet Fix from $1,9502018-08-03 CRITICAL 9.8 CVE-2018-14579 GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by… Golemcms after 2008-12-24 Fix from $2,3002018-07-24 CRITICAL 9.8 CVE-2018-1999022 PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's vali… Html Quickform after 4.6.37 Fix from $2,3002018-07-23 HIGH 8.8 CVE-2018-1999023 The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in co… The Battle For Wesnoth after 1.14.3 Fix from $1,9502018-07-23 CRITICAL 9.8 CVE-2018-1999019 Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.ph… Chamilo Lms Patch available Fix from $2,3002018-07-23 HIGH 8.8 CVE-2018-14421 SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admi… Seacms Mitigation only Fix from $1,9502018-07-20 CRITICAL 9.8 CVE-2014-2302 The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by i… Webedition Cms 6.2.7.0 / 6.3.8+ Fix from $2,3002018-07-19 CRITICAL 9.8 CVE-2018-7602 KEVEPSS 99% A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple … Drupal 7.59 / 8.4.8+ Fix from $2,3002018-07-19 CRITICAL 9.8 CVE-2018-14399 libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SR… Phpcms Mitigation only Fix from $2,3002018-07-19 HIGH 8.1 CVE-2018-8284EPSS 39% A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Inje… .net Framework Patch available Fix from $1,9502018-07-11 HIGH 8.8 CVE-2018-2427 SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allow… Businessobjects Business Intelligence Patch available Fix from $1,9502018-07-10 CRITICAL 9.8 CVE-2018-13818EPSS 7% Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is n… Twig 2.4.4+ Fix from $2,3002018-07-10