Skip to main content

CWE archive

CWE-74 CVEs

Programmatic archive

4,975 CVEs tagged with CWE-74242 Critical, 531 High, 3,008 Medium, 1,193 Low, 1 Unrated.

CVE-2015-1975

Published Apr 3, 2018

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory S…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4106

Published Apr 3, 2018

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assist…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1319

Published Mar 15, 2018

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including X…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6220

Published Mar 15, 2018

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vul…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1000130

Published Mar 14, 2018

A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5377

Published Mar 6, 2018

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-32…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-5799

Published Feb 15, 2018

A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions pr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7032

Published Feb 14, 2018

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6603

Published Feb 7, 2018

Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6519

Published Feb 2, 2018

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14523

Published Jan 26, 2018

WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely becaus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18049

Published Jan 23, 2018

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14094

Published Jan 19, 2018

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-7952

Published Jan 12, 2018

The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter applicati…

CVSS 7.8 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2017-15714

Published Jan 4, 2018

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000493

Published Jan 3, 2018

Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000454

Published Jan 2, 2018

CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000453

Published Jan 2, 2018

CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4578

Published Dec 29, 2017

jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by le…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3695

Published Dec 29, 2017

The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leverag…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15313

Published Dec 22, 2017

Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affected device.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16766

Published Dec 22, 2017

An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17790

Published Dec 20, 2017

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 4,851-4,875 of 4,975 CVEsPage 195 of 199