Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-1000196
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applicat…
October
after 1.0.412
HIGH 8.8
CVE-2014-4000
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized …
Cacti
1.0.0+
HIGH 8.1
CVE-2017-15806EPSS 11%
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the …
Mail
1.8.2+
CRITICAL 9.8
CVE-2017-16783EPSS 8%
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Cms Made Simple
No fix yet
HIGH 8.8
CVE-2017-7411EPSS 67%
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the …
Tuleap
after 9.6
HIGH 7.2
CVE-2017-15935
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrat…
Pandora Fms
Mitigation only
CRITICAL 9.8
CVE-2017-15376
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP por…
Mobaxterm
No fix yet
HIGH 8.8
CVE-2017-14353
A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, cou…
Ucmdb Foundation Software
No fix yet
HIGH 8.8
CVE-2015-6576
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an …
Bamboo
5.8.5 / 5.9.7+
HIGH 7.0
CVE-2017-13676
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL f…
Remove \& Reinstall
Mitigation only
HIGH 8.8
CVE-2017-14764
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.
Genixcms
No fix yet
HIGH 8.8
CVE-2014-9463EPSS 15%
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to…
Vbseo
No fix yet
HIGH 7.8
CVE-2017-2809
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary …
Ansible Vault
after 1.0.4
HIGH 7.8
CVE-2017-8759 KEVEPSS 87%
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or app…
.net Framework
Patch available
CRITICAL 9.0
CVE-2015-8351EPSS 37%
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote a…
Gwolle Guestbook
after 1.5.3
HIGH 7.2
CVE-2015-9227
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote admini…
Alegrocart
No fix yet
HIGH 8.8
CVE-2017-14146
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\…
Helpdezk
Mitigation only
CRITICAL 9.8
CVE-2017-3897EPSS 12%
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security…
Livesafe
after 16.0.2
MEDIUM 5.3
CVE-2014-8677
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databa…
Soplanning
after 1.32
CRITICAL 9.8
CVE-2017-0899EPSS 11%
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem…
Debian Linux
after 2.6.12
HIGH 8.8
CVE-2017-1440
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted…
Emptoris Services Procurement
Patch available
HIGH 8.8
CVE-2017-10844
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
Basercms
after 4.0.5
HIGH 7.8
CVE-2014-8872
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other mod…
Fritz\!box 6810 Lte Firmware
No fix yet
HIGH 8.8
CVE-2017-10835
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vect…
Scr02hd Firmware
after 1.0.3.1000
MEDIUM 5.4
CVE-2017-6782
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in t…
Prime Infrastructure
Mitigation only
CRITICAL 9.8
CVE-2011-0469
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
Opensuse
Patch available
HIGH 7.8
CVE-2017-1469
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation…
Infosphere Information Server
Mitigation only
MEDIUM 6.8
CVE-2017-3753
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnera…
Ideacentre 300 20ish Firmware
Mitigation only
HIGH 8.8
CVE-2017-11760
uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concat…
Projeqtor
after 6.3.1
CRITICAL 9.8
CVE-2017-11715
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins…
Metinfo
after 5.3.17