Vulnerabilities (CVE)

Filtered by CWE-94
Total 3303 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-9891 1 Tldp 1 Advanced Bash-scripting Guide 2020-08-24 10.0 HIGH 9.8 CRITICAL
The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.
CVE-2019-5509 1 Netapp 1 Ontap Select Deploy Administration Utility 2020-08-24 7.5 HIGH 9.8 CRITICAL
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.
CVE-2019-10100 1 Jetbrains 1 Youtrack Integration 2020-08-24 7.5 HIGH 9.8 CRITICAL
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.
CVE-2019-15318 1 Yikesinc 1 Easy Forms For Mailchimp 2020-08-24 7.5 HIGH 9.8 CRITICAL
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
CVE-2018-7951 1 Huawei 40 1288h V5, 1288h V5 Firmware, 2288h V5 and 37 more 2020-08-24 9.0 HIGH 8.8 HIGH
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.
CVE-2019-17300 1 Sugarcrm 1 Sugarcrm 2020-08-24 6.5 MEDIUM 8.8 HIGH
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.
CVE-2018-18836 1 My-netdata 1 Netdata 2020-08-24 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/api/web_api_v1.c.
CVE-2019-17308 1 Sugarcrm 1 Sugarcrm 2020-08-24 6.5 MEDIUM 8.8 HIGH
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
CVE-2019-10863 1 Combodo 1 Teemip 2020-08-24 6.5 MEDIUM 7.2 HIGH
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.
CVE-2018-1133 1 Moodle 1 Moodle 2020-08-24 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
CVE-2018-20988 1 Google Forms Project 1 Google Forms 2020-08-24 5.0 MEDIUM 7.5 HIGH
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
CVE-2019-3427 1 Zte 2 Zxcdn Iamweb, Zxcdn Iamweb Firmware 2020-08-24 6.5 MEDIUM 7.2 HIGH
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.
CVE-2018-21005 1 Bbpress Move Topics Project 1 Bbpress Move Topics 2020-08-24 7.5 HIGH 9.8 CRITICAL
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
CVE-2019-16108 1 Phpbb 1 Phpbb 2020-08-24 5.0 MEDIUM 7.5 HIGH
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
CVE-2019-12844 1 Jetbrains 1 Teamcity 2020-08-24 4.3 MEDIUM 6.1 MEDIUM
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
CVE-2019-7692 1 Cim Project 1 Cim 2020-08-24 7.5 HIGH 9.8 CRITICAL
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder.
CVE-2018-1000070 1 Bitmessage 1 Pybitmessage 2020-08-24 6.8 MEDIUM 8.8 HIGH
Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnerability in main program, file src/messagetypes/__init__.py function constructObject that can result in Code Execution. This attack appears to be exploitable via remote attacker using a malformed message which must be processed by the victim - e.g. arrive from any sender on bitmessage network. This vulnerability appears to have been fixed in v0.6.3.
CVE-2019-19909 1 Sfu 1 Open Journal System 2020-08-24 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
CVE-2019-17303 1 Sugarcrm 1 Sugarcrm 2020-08-24 6.5 MEDIUM 8.8 HIGH
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
CVE-2018-1808 1 Ibm 1 Websphere Commerce 2020-08-24 6.5 MEDIUM 8.8 HIGH
IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.