Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-47560
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute…
Qumagie
Mitigation only
CRITICAL 9.8
CVE-2023-51812
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
Ax3 Firmware
No fix yet
HIGH 8.8
CVE-2023-52137
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames,…
Verify Changed Files
17.0.0+
HIGH 7.8
CVE-2023-50445EPSS 9%
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N…
Gl Mt1300 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51664
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo…
Changed Files
41.0.0+
HIGH 7.2
CVE-2023-49226
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users w…
Balance Two Firmware
8.4.0+
CRITICAL 9.8
CVE-2023-51014
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig in…
Ex1800t Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51016
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .…
Ex1800t Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51025
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCf…
Ex1800t Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51707
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffe…
Arrayos Ag
9.4.0.505+
CRITICAL 9.8
CVE-2023-50989
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
I29 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-50983
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
I29 Firmware
Mitigation only
HIGH 8.8
CVE-2023-6940
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
Mlflow
2.9.2+
HIGH 7.2
CVE-2023-39509
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o…
Cpp13 Firmware
after 8.90
CRITICAL 9.8
CVE-2023-6848
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of t…
Kodbox
1.48.04+
CRITICAL 9.8
CVE-2023-50089
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs dur…
Wnr2000 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-50917EPSS 38%
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majo…
Majordomo
2023-11-15+
HIGH 7.2
CVE-2023-49898
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of …
Streampark
2.1.2+
HIGH 8.1
CVE-2023-6572
Command Injection in GitHub repository gradio-app/gradio prior to main.
Gradio
4.14.0+
HIGH 8.8
CVE-2023-25643
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters,…
Mc801a Firmware
Mitigation only
HIGH 7.2
CVE-2023-48702
Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file …
Jellyfin
10.8.13+
HIGH 8.8
CVE-2023-48791
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7…
Fortiportal
after 7.0.6
HIGH 8.8
CVE-2023-47576
An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.
Rely Pcie Firmware
Mitigation only
CRITICAL 9.8
CVE-2013-2513
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
Flash Tool
after 0.6.0
MEDIUM 6.4
CVE-2023-49587
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam…
Solution Manager
Mitigation only
CRITICAL 9.8
CVE-2023-40301
NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.
Ngeniuspulse
Mitigation only
CRITICAL 9.8
CVE-2023-49431
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
Ax9 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-49435
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
Ax9 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-49436
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
Ax9 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-49428
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
Ax12 Firmware
No fix yet