Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-38865
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/we…
Cf Xr11 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-39293
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor t…
Mivoice Office 400
after 7.0.9281
MEDIUM 6.8
CVE-2023-40293
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.
Harman Infotainment
No fix yet
CRITICAL 9.8
CVE-2023-38034
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a …
Unifi Uap Firmware
after 6.5.53
CRITICAL 9.8
CVE-2023-39008
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 2…
Opnsense
23.7+
CRITICAL 9.8
CVE-2023-39001
A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow…
Opnsense
23.7+
HIGH 7.2
CVE-2023-32781EPSS 14%
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write p…
Prtg Network Monitor
23.3.86.1520+
HIGH 7.2
CVE-2023-32782EPSS 56%
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permis…
Prtg Network Monitor
23.3.86.1520+
CRITICAL 9.8
CVE-2023-26310
There is a command injection problem in the old version of the mobile phone backup app.
Coloros
No fix yet
HIGH 7.8
CVE-2023-35390
.NET and Visual Studio Remote Code Execution Vulnerability
.net
6.0.21 / 7.0.10+
HIGH 8.8
CVE-2023-39523
ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a pos…
Scancode.io
32.5.1+
HIGH 8.8
CVE-2023-38921
Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via…
Wg302v2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-38928
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.
R7100lg Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-38690
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be …
Matrix Irc Bridge
1.0.1+
CRITICAL 9.8
CVE-2023-38941
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCre…
Django Sspanel
Mitigation only
CRITICAL 9.8
CVE-2023-38942
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.
Dango Translator
Patch available
CRITICAL 9.8
CVE-2023-4120EPSS 65%
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown process…
Smart S85f
after 20230722
CRITICAL 9.8
CVE-2023-37679EPSS 99%
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
Mirth Connect
Mitigation only
CRITICAL 9.8
CVE-2023-26317
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external…
Xiaomi Router Firmware
2023.2+
MEDIUM 6.3
CVE-2023-3739
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbit…
Chrome
115.0.5790.131+
MEDIUM 5.5
CVE-2023-31429
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, …
Fabric Operating System
9.1.1c+
HIGH 8.8
CVE-2023-3718
An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results i…
Arubaos Cx
after 10.11.1010
CRITICAL 9.8
CVE-2022-39986EPSS 99%
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter …
Raspap
after 2.8.7
HIGH 8.8
CVE-2022-39987EPSS 39%
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entit…
Raspap
after 2.9.2
CRITICAL 9.8
CVE-2023-34960EPSS 99%
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via …
Chamilo
after 1.11.18
CRITICAL 9.8
CVE-2023-37214
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
Ero1xs Pro Firmware
No fix yet
HIGH 8.8
CVE-2023-28012
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
Bigfix Mobile
Mitigation only
HIGH 7.2
CVE-2023-28130EPSS 21%
Local user may lead to privilege escalation using Gaia Portal hostnames page.
Gaia Portal
No fix yet
CRITICAL 9.8
CVE-2023-37794
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.
Fbm 291w Firmware
No fix yet
CRITICAL 9.8
CVE-2023-38336
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-20…
Netkit
No fix yet