Vulnerabilities (CVE)

Filtered by CWE-1321
Total 582 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11135 1 Quest 1 Kace System Management Appliance 2026-06-17 6.0 MEDIUM 8.8 HIGH
The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks.
CVE-2011-10019 1 Spreecommerce 1 Spree 2026-06-16 N/A 9.8 CRITICAL
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.