Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2018-1104 Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar… Ansible Tower after 3.2.3 Fix from $1,9502018-05-02 HIGH 7.2 CVE-2018-10642EPSS 7% Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platfo… Itop after 2.4.1 Fix from $1,9502018-05-02 CRITICAL 9.8 CVE-2018-8938 A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr… Whatsup Gold 18.0+ Fix from $2,3002018-05-01 CRITICAL 9.8 CVE-2018-10574 site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeSto… Bigtree Cms after 4.2.22 Fix from $2,3002018-04-30 HIGH 7.2 CVE-2018-10515 In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitab… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-27 HIGH 7.2 CVE-2018-10517EPSS 12% In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploi… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-27 CRITICAL 9.8 CVE-2018-10429 Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php. Cosmo No fix yet Fix from $2,3002018-04-26 MEDIUM 5.6 CVE-2017-1721 IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumsta… Qradar Security Information And Event Manager 7.2.8+ Fix from $1,6002018-04-26 HIGH 7.8 CVE-2018-8974 Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, related to code injection via a cra… Microbetrace Patch available Fix from $1,9502018-04-26 HIGH 7.8 CVE-2018-9113 Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 allows remote attackers to execute arbitrary code, related to code injection via a cra… Microbetrace Patch available Fix from $1,9502018-04-26 HIGH 7.2 CVE-2018-10235 POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because … Poscms No fix yet Fix from $1,9502018-04-19 HIGH 7.2 CVE-2018-10236 POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an … Poscms No fix yet Fix from $1,9502018-04-19 CRITICAL 9.8 CVE-2018-10133 PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel functi… Pbootcms No fix yet Fix from $2,3002018-04-16 HIGH 7.2 CVE-2018-10086 CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval… Cms Made Simple after 2.2.7 Fix from $1,9502018-04-13 HIGH 8.8 CVE-2018-1028EPSS 19% A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft O… Excel Services Patch available Fix from $1,9502018-04-12 CRITICAL 9.8 CVE-2018-1273 KEVEPSS 96% Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused … Spring Data Rest after 3.0.5 Fix from $2,3002018-04-11 CRITICAL 9.8 CVE-2018-1275EPSS 58% Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP ove… Spring Framework 4.3.16 / 5.0.5+ Fix from $2,3002018-04-11 CRITICAL 9.8 CVE-2018-9847 In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by plac… Gxlcms Qy No fix yet Fix from $2,3002018-04-07 CRITICAL 9.8 CVE-2018-9848 In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by f… Gxlcms Qy No fix yet Fix from $2,3002018-04-07 CRITICAL 9.8 CVE-2018-1270EPSS 77% Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP ove… Spring Framework 4.3.16 / 5.0.5+ Fix from $2,3002018-04-06 MEDIUM 6.1 CVE-2017-3967 Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers… Network Security Manager 8.2.7.42.2+ Fix from $1,6002018-04-04 CRITICAL 9.8 CVE-2018-9174 sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modify… Dedecms Mitigation only Fix from $2,3002018-04-02 CRITICAL 9.8 CVE-2018-9175 DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within th… Dedecms Mitigation only Fix from $2,3002018-04-02 CRITICAL 9.8 CVE-2018-8823EPSS 51% modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2… Responsive Mega Menu Pro after 1.7.2.5 Fix from $2,3002018-03-28 CRITICAL 9.8 CVE-2014-2293 Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or exec… Zikula Application Framework after 1.3.6 Fix from $2,3002018-03-26 HIGH 7.5 CVE-2018-8966 An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a php… Zzcms No fix yet Fix from $1,9502018-03-24 CRITICAL 9.8 CVE-2018-1207EPSS 90% Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauth… Emc Idrac7 2.52.52.52+ Fix from $2,3002018-03-23 CRITICAL 9.8 CVE-2017-1789 IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 13… Tivoli Monitoring Mitigation only Fix from $2,3002018-03-22 CRITICAL 9.8 CVE-2018-8073 Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis e… Yii 2.0.15+ Fix from $2,3002018-03-21 HIGH 8.1 CVE-2018-8074 Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with th… Yii 2.0.15+ Fix from $1,9502018-03-21