Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-3608
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attack…
Antivirus \+ Security
after 12.0.1191
MEDIUM 5.4
CVE-2017-1242
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…
Rational Quality Manager
after 6.0.5
MEDIUM 6.1
CVE-2017-1248
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…
Rational Quality Manager
after 6.0.5
MEDIUM 5.4
CVE-2017-1329
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…
Rational Quality Manager
after 6.0.5
CRITICAL 9.8
CVE-2018-13043
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co…
Devscripts
after 2.18.3
HIGH 8.8
CVE-2018-12994
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.
Onefilecms
after 2012-04-14
HIGH 8.8
CVE-2018-12995
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.
Onefilecms
after 2012-04-14
CRITICAL 9.8
CVE-2017-7465
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2018-11587
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…
Centreon
Patch available
CRITICAL 9.8
CVE-2018-12531
An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulne…
Metinfo
No fix yet
CRITICAL 9.8
CVE-2017-3907
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows…
Mcafee Threat Intelligence Exchange
Mitigation only
HIGH 8.8
CVE-2018-5158EPSS 10%
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF fil…
Debian Linux
52.8.0 / 60.0+
HIGH 8.8
CVE-2017-7798
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, t…
Debian Linux
52.3.0 / 55.0+
CRITICAL 9.8
CVE-2018-6512
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …
Pe Razor Server
1.9.0.0 / 2018.1.1+
CRITICAL 9.8
CVE-2018-11228EPSS 7%
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code executio…
Crestron Toolbox Protocol Firmware
2.001.0037.001+
CRITICAL 9.8
CVE-2017-16151
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent …
Electron
1.7.8+
CRITICAL 9.8
CVE-2017-16100EPSS 5%
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Dns Sync
after 0.1.1
CRITICAL 9.8
CVE-2017-16082EPSS 11%
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. The…
Pg
2.11.2 / 3.6.4+
CRITICAL 9.8
CVE-2017-16042
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitra…
Growl
1.10.2+
CRITICAL 9.8
CVE-2017-16020
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands …
Summit
after 0.1.21
HIGH 8.8
CVE-2018-7950
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validatio…
1288h V5 Firmware
Mitigation only
HIGH 8.8
CVE-2018-7951
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validatio…
1288h V5 Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-10541
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend o…
Shell Quote
1.6.1+
CRITICAL 9.8
CVE-2016-10546
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design docu…
Pouchdb
after 6.0.4
MEDIUM 6.1
CVE-2016-10548
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on t…
Reduce Css Calc
after 1.2.4
MEDIUM 6.1
CVE-2014-10065
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascri…
Remarkable
1.4.1+
HIGH 8.8
CVE-2018-1133EPSS 32%
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval…
Moodle
after 3.4.2
CRITICAL 9.8
CVE-2018-1260EPSS 8%
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contai…
Spring Security Oauth
after 2.3.2
CRITICAL 9.8
CVE-2018-2418
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could th…
Maxdb Odbc Driver
7.9.09.07+
CRITICAL 9.8
CVE-2018-10740
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php f…
Axublog
No fix yet