Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-7402EPSS 5%
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanage…
Pixie
No fix yet
CRITICAL 9.8
CVE-2014-3927
mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code.
Mrlg4php
after 1.0.7
CRITICAL 9.8
CVE-2017-7321
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parame…
Modx Revolution
after 2.5.4
CRITICAL 9.8
CVE-2017-7324
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path paramete…
Modx Revolution
after 2.5.4
CRITICAL 9.8
CVE-2014-3582
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo…
Ambari
after 2.2.2
HIGH 7.0
CVE-2017-6455
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variab…
Ntp
Patch available
CRITICAL 9.8
CVE-2015-0855
The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file…
Pitivi
after 0.94
HIGH 7.8
CVE-2016-1602
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise De…
Linux Enterprise Desktop
Mitigation only
MEDIUM 6.7
CVE-2017-6186
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and ear…
Antivirus Plus
after 12.0
HIGH 8.0
CVE-2016-8020EPSS 11%
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…
Virusscan Enterprise
after 2.0.3
CRITICAL 9.1
CVE-2017-2968
Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability.
Campaign
after 16.4
HIGH 7.0
CVE-2016-8354
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Si…
Unity Pro
after 11.0
CRITICAL 9.8
CVE-2015-8771
The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
Gosa Plugin
Patch available
CRITICAL 9.8
CVE-2016-5726
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via th…
Simple Machines Forum
Patch available
HIGH 8.8
CVE-2016-5727
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via ve…
Simple Machines Forum
Patch available
CRITICAL 9.8
CVE-2016-6175EPSS 20%
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms heade…
Php Gettext
after 1.0.12
HIGH 8.4
CVE-2016-7102
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in t…
Owncloud Desktop Client
after 2.2.2
CRITICAL 9.8
CVE-2016-2242EPSS 7%
Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
Exponent Cms
Patch available
CRITICAL 9.8
CVE-2016-10157
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated …
Netsession
No fix yet
CRITICAL 9.8
CVE-2017-5543
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data i…
Subrion
Patch available
MEDIUM 5.3
CVE-2016-10072
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but…
Wampserver
No fix yet
HIGH 7.3
CVE-2016-7966
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on t…
Debian Linux
after 4.4.0
HIGH 8.1
CVE-2016-7967
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security…
Kmail
after 5.3.0
MEDIUM 6.5
CVE-2016-7968
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and includ…
Kmail
after 5.3.0
CRITICAL 9.8
CVE-2016-7954EPSS 8%
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. …
Bundler
Patch available
HIGH 7.8
CVE-2016-9949EPSS 18%
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it…
Ubuntu Linux
after 12.10
HIGH 7.5
CVE-2016-9862
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4…
phpMyAdmin
Patch available
HIGH 7.1
CVE-2016-5424
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users…
Debian Linux
after 9.1.22
CRITICAL 9.8
CVE-2016-1000003
Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code.
Mirror Manager
after 0.7.2
HIGH 8.8
CVE-2016-5149
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to …
Chrome
after 52.0.2743.116