Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-11675
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows re…
Zen Cart
Mitigation only
CRITICAL 9.8
CVE-2017-11459
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr…
Trex
Mitigation only
CRITICAL 9.8
CVE-2017-11585
dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.
Finecms
No fix yet
HIGH 8.8
CVE-2015-3638
phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts…
Phpmybackuppro
after 2.5
HIGH 7.5
CVE-2015-3640
phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowled…
Phpmybackuppro
after 2.5
HIGH 8.8
CVE-2017-9822 KEVEPSS 95%
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Dotnetnuke
9.1.1+
HIGH 7.8
CVE-2017-11421
gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a l…
Gnome Exe Thumbnailer
after 0.9.4
HIGH 7.2
CVE-2015-0249
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…
Roller
Mitigation only
CRITICAL 9.8
CVE-2017-11167
FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence i…
Finecms
No fix yet
CRITICAL 9.8
CVE-2017-10968
In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "<?php" in a route…
Finecms
No fix yet
CRITICAL 9.8
CVE-2017-9841 KEVEPSS 100%
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginn…
Phpunit
5.6.3+
MEDIUM 6.6
CVE-2017-6325
The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect w…
Messaging Gateway
after 10.6.2
CRITICAL 9.8
CVE-2017-9807
An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" p…
Openwebif
after 1.2.4
HIGH 8.8
CVE-2017-9774
Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.
Horde Image Api
Mitigation only
CRITICAL 9.8
CVE-2017-9771
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_…
Websitebaker
Patch available
HIGH 8.8
CVE-2015-2252
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a…
Oceanstor Uds Firmware
Mitigation only
HIGH 8.8
CVE-2017-9442
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, rel…
Bigtree Cms
after 4.2.18
HIGH 7.8
CVE-2015-6531
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmwar…
Pan Os
after 6.0
HIGH 8.8
CVE-2017-8402
PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.
Pivotx
Patch available
CRITICAL 9.8
CVE-2017-7494 KEVEPSS 99%
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up…
Debian Linux
4.4.0 / 4.4.14+
HIGH 7.2
CVE-2017-8912
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.ph…
Cms Made Simple
Patch available
HIGH 8.8
CVE-2017-7911
A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified…
Kaa Iot Platform
Mitigation only
HIGH 7.0
CVE-2017-8284
The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the inst…
Qemu
after 2.8.1.1
HIGH 8.8
CVE-2016-4895
SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.
Setucocms
No fix yet
HIGH 8.8
CVE-2017-7694
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to e…
Symphony
after 2.6.11
CRITICAL 9.8
CVE-2017-7691
A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.
Trex
Mitigation only
CRITICAL 9.8
CVE-2017-7625
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execu…
Fiyo Cms
No fix yet
HIGH 8.8
CVE-2016-5072
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Ente…
Oxid Eshop
after 5.2.8
HIGH 8.8
CVE-2017-7570
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .j…
Pivotx
No fix yet
HIGH 8.8
CVE-2017-4964
Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the di…
Bosh Azure Cpi
Patch available