Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2011-3178
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e…
Open Build Service
2.3.0+
HIGH 7.2
CVE-2018-8756
Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in t…
Yzmcms
No fix yet
CRITICAL 9.8
CVE-2018-7756EPSS 61%
RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remo…
Dewesoft
No fix yet
CRITICAL 9.8
CVE-2018-5779
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
Mitigation only
CRITICAL 9.8
CVE-2018-5780
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
Mitigation only
CRITICAL 9.8
CVE-2018-5781
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
Mitigation only
CRITICAL 9.8
CVE-2018-5782EPSS 19%
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
No fix yet
CRITICAL 9.8
CVE-2018-8097EPSS 6%
io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.
Eve
0.7.5+
HIGH 8.8
CVE-2018-1000070
Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnera…
Pybitmessage
Patch available
HIGH 7.5
CVE-2018-7466EPSS 6%
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES da…
Testlink
after 1.9.16
CRITICAL 9.8
CVE-2018-6488
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to all…
Ucmdb Configuration Manager
Mitigation only
HIGH 8.1
CVE-2018-7271
An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering i…
Metinfo
No fix yet
HIGH 7.8
CVE-2017-16670
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL pro…
Soapui
No fix yet
HIGH 8.8
CVE-2018-6889EPSS 7%
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the …
Typesetter
No fix yet
HIGH 7.8
CVE-2018-6574EPSS 8%
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, …
Go
after 1.8.6
CRITICAL 9.8
CVE-2018-0007
An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may…
Junos
Mitigation only
HIGH 8.8
CVE-2018-2363
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrar…
Netweaver
after 7.52
HIGH 8.1
CVE-2017-16905
The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and conseq…
Tinycards
1.0+
CRITICAL 9.8
CVE-2017-1000480
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize t…
Smarty
3.1.32+
CRITICAL 9.8
CVE-2017-17098EPSS 7%
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary …
Gps Tracking Software
after 3.0
MEDIUM 6.1
CVE-2017-17649
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
Readymade Video Sharing Script
No fix yet
HIGH 7.2
CVE-2017-16682
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administra…
Netweaver Internet Transaction Server
after 7.52
CRITICAL 9.8
CVE-2016-5713
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to …
Puppet Agent
1.6.0+
HIGH 8.8
CVE-2017-14198
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause…
Matrix
after 5.3.6.0
CRITICAL 9.8
CVE-2017-1001002
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could resu…
Math.js
after 3.17.0
HIGH 8.8
CVE-2017-1001004
typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name cou…
Typed Function
0.10.6+
HIGH 8.8
CVE-2017-16664
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t…
Debian Linux
3.3.20 / 4.0.26+
HIGH 8.8
CVE-2017-16544EPSS 6%
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i…
Debian Linux
after 1.27.2
MEDIUM 6.1
CVE-2017-14077
HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_US…
Securimage
after 3.6.4
HIGH 8.1
CVE-2017-16871
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd…
Updraftplus
after 1.13.12