Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-1104
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…
Ansible Tower
after 3.2.3
HIGH 7.2
CVE-2018-10642EPSS 7%
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platfo…
Itop
after 2.4.1
CRITICAL 9.8
CVE-2018-8938
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…
Whatsup Gold
18.0+
CRITICAL 9.8
CVE-2018-10574
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeSto…
Bigtree Cms
after 4.2.22
HIGH 7.2
CVE-2018-10515
In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitab…
Cms Made Simple
after 2.2.7
HIGH 7.2
CVE-2018-10517EPSS 12%
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploi…
Cms Made Simple
after 2.2.7
CRITICAL 9.8
CVE-2018-10429
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.
Cosmo
No fix yet
MEDIUM 5.6
CVE-2017-1721
IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumsta…
Qradar Security Information And Event Manager
7.2.8+
HIGH 7.8
CVE-2018-8974
Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, related to code injection via a cra…
Microbetrace
Patch available
HIGH 7.8
CVE-2018-9113
Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 allows remote attackers to execute arbitrary code, related to code injection via a cra…
Microbetrace
Patch available
HIGH 7.2
CVE-2018-10235
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because …
Poscms
No fix yet
HIGH 7.2
CVE-2018-10236
POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an …
Poscms
No fix yet
CRITICAL 9.8
CVE-2018-10133
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel functi…
Pbootcms
No fix yet
HIGH 7.2
CVE-2018-10086
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval…
Cms Made Simple
after 2.2.7
HIGH 8.8
CVE-2018-1028EPSS 19%
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft O…
Excel Services
Patch available
CRITICAL 9.8
CVE-2018-1273 KEVEPSS 96%
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused …
Spring Data Rest
after 3.0.5
CRITICAL 9.8
CVE-2018-1275EPSS 58%
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP ove…
Spring Framework
4.3.16 / 5.0.5+
CRITICAL 9.8
CVE-2018-9847
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by plac…
Gxlcms Qy
No fix yet
CRITICAL 9.8
CVE-2018-9848
In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by f…
Gxlcms Qy
No fix yet
CRITICAL 9.8
CVE-2018-1270EPSS 77%
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP ove…
Spring Framework
4.3.16 / 5.0.5+
MEDIUM 6.1
CVE-2017-3967
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers…
Network Security Manager
8.2.7.42.2+
CRITICAL 9.8
CVE-2018-9174
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modify…
Dedecms
Mitigation only
CRITICAL 9.8
CVE-2018-9175
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within th…
Dedecms
Mitigation only
CRITICAL 9.8
CVE-2018-8823EPSS 51%
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2…
Responsive Mega Menu Pro
after 1.7.2.5
CRITICAL 9.8
CVE-2014-2293
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or exec…
Zikula Application Framework
after 1.3.6
HIGH 7.5
CVE-2018-8966
An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a php…
Zzcms
No fix yet
CRITICAL 9.8
CVE-2018-1207EPSS 90%
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauth…
Emc Idrac7
2.52.52.52+
CRITICAL 9.8
CVE-2017-1789
IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 13…
Tivoli Monitoring
Mitigation only
CRITICAL 9.8
CVE-2018-8073
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis e…
Yii
2.0.15+
HIGH 8.1
CVE-2018-8074
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with th…
Yii
2.0.15+