CVE-2026-9082 · 2026-07-14 · pending_review
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。
CVE-2026-9082 · 2026-07-14 · pending_review
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-56290 · 2026-07-14 · pending_review
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
CVE-2026-41940 · 2026-07-14 · pending_review
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control …
CVE-2025-54068 · 2026-07-14 · pending_review
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CVE-2025-49704 · 2026-07-15 · pending_review
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypa…
CVE-2024-38856 · 2026-07-15 · pending_review
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
CVE-2024-38094 · 2026-07-15 · pending_review
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
CVE-2024-34102 · 2026-07-15 · pending_review
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
CVE-2024-32113 · 2026-07-15 · pending_review
Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
CVE-2023-24955 · 2026-07-15 · pending_review
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
CVE-2023-22527 · 2026-07-15 · pending_review
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
CVE-2022-26134 · 2026-07-15 · pending_review
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
CVE-2022-24112 · 2026-07-15 · pending_review
Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
CVE-2022-22965 · 2026-07-15 · pending_review
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-22963 · 2026-07-15 · pending_review
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local…
CVE-2022-22947 · 2026-07-15 · pending_review
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
CVE-2021-45046 · 2026-07-15 · pending_review
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default …
CVE-2021-44228 · 2026-07-18 · pending_review
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE-2021-42013 · 2026-07-18 · pending_review
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denie…
CVE-2021-41773 · 2026-07-18 · pending_review
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all deni…
CVE-2021-3129 · 2026-07-15 · pending_review
Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
CVE-2021-22205 · 2026-07-18 · pending_review
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improper…
CVE-2020-25213 · 2026-07-18 · pending_review
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
CVE-2020-1956 · 2026-07-15 · pending_review
Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.
CVE-2020-17530 · 2026-07-18 · pending_review
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
CVE-2020-17496 · 2026-07-18 · pending_review
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an …
CVE-2020-14882 · 2026-07-18 · pending_review
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
CVE-2020-14750 · 2026-07-18 · pending_review
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
CVE-2020-14644 · 2026-07-15 · pending_review
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remot…
CVE-2020-1147 · 2026-07-18 · pending_review
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an atta…
CVE-2019-9978 · 2026-07-18 · pending_review
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2019-9082 · 2026-07-18 · pending_review
ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
CVE-2019-7609 · 2026-07-18 · pending_review
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
CVE-2019-6340 · 2026-07-15 · pending_review
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2019-3398 · 2026-07-18 · pending_review
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code …
CVE-2019-3396 · 2026-07-18 · pending_review
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
CVE-2019-17558 · 2026-07-18 · pending_review
The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-16759 · 2026-07-18 · pending_review
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CVE-2019-16278 · 2026-07-15 · pending_review
Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
CVE-2019-11581 · 2026-07-15 · pending_review
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
CVE-2019-11043 · 2026-07-15 · pending_review
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
CVE-2019-1003030 · 2026-07-15 · pending_review
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2019-0604 · 2026-07-18 · pending_review
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the Sha…
CVE-2019-0193 · 2026-07-18 · pending_review
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CVE-2018-7602 · 2026-07-15 · pending_review
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7600 · 2026-07-18 · pending_review
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CVE-2018-20062 · 2026-07-18 · pending_review
ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
CVE-2018-1273 · 2026-07-15 · pending_review
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
CVE-2018-11776 · 2026-07-18 · pending_review
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying con…
CVE-2017-9805 · 2026-07-18 · pending_review
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.