VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

664 CVEsRSS

CVE-2018-7602Critical· 9.8CISA KEVPoC
8y ago

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This …

▾ Hadaldrupal · drupalEPSS 99%via NVD
CVE-2018-1273Critical· 9.8CISA KEVPoC
8y ago

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user…

▾ Hadalbroadcom · spring_data_commonsEPSS 97%via NVD
CVE-2015-5721Critical· 9.8
10y ago

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

▾ Midnightmisp-project · mispEPSS 2.6%via NVD
CVE-1999-0509Critical· 10.0
30y ago

Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.

Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.

▾ MidnightEPSS 33%via NVD
CWE-94 vulnerabilities (CVEs) — page 23 · VulnSea