Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-94
Total 2906 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19180 1 Yunucms 1 Yunucms 2018-12-12 7.5 HIGH 9.8 CRITICAL
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.
CVE-2018-19220 1 Laobancms 1 Laobancms 2018-12-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
CVE-2017-11459 1 Sap 1 Trex 2018-12-10 7.5 HIGH 9.8 CRITICAL
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.
CVE-2015-1311 1 Sap 1 Hana Extend Application Services 2018-12-10 10.0 HIGH N/A
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2014-8660 1 Sap 1 Document Management Services 2018-12-10 7.2 HIGH N/A
SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.
CVE-2018-7633 1 Adbglobal 1 Epicentro 2018-12-10 7.5 HIGH 9.8 CRITICAL
Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request.
CVE-2018-18835 1 Doccms 1 Doccms 2018-12-06 7.5 HIGH 9.8 CRITICAL
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
CVE-2018-18892 1 1234n 1 Minicms 2018-12-03 7.5 HIGH 9.8 CRITICAL
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
CVE-2018-18426 1 S-cms 1 S-cms 2018-12-03 9.0 HIGH 8.8 HIGH
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter.
CVE-2018-18461 1 Kibokolabs 1 Arigato Autoresponder And Newsletter 2018-11-30 7.5 HIGH 9.8 CRITICAL
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.
CVE-2018-18083 1 Comsenz 1 Duomicms 2018-11-29 7.5 HIGH 9.8 CRITICAL
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
CVE-2015-9272 1 Videowhisper 1 Video Presentation 2018-11-23 7.5 HIGH 9.8 CRITICAL
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
CVE-2013-2134 1 Apache 1 Struts 2018-11-23 9.3 HIGH N/A
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
CVE-2013-2135 1 Apache 1 Struts 2018-11-23 9.3 HIGH N/A
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
CVE-2018-0674 1 Hibara 1 Attachecase 2018-11-20 6.8 MEDIUM 7.8 HIGH
AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.
CVE-2018-0675 1 Hibara 1 Attachecase 2018-11-20 6.8 MEDIUM 7.8 HIGH
AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
CVE-2018-17126 1 Chshcms 1 Cscms 2018-11-19 7.5 HIGH 9.8 CRITICAL
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
CVE-2018-15886 1 Monstra 1 Monstra 2018-11-14 6.5 MEDIUM 7.2 HIGH
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP code by placing this code after a <?php substring.
CVE-2018-16604 1 Nibbleblog 1 Nibbleblog 2018-11-14 6.5 MEDIUM 7.2 HIGH
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").
CVE-2018-16343 1 Seacms 1 Seacms 2018-11-13 6.5 MEDIUM 7.2 HIGH
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.