Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2023-33298
com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usingCAPath.
Xpc Helpertool
No fix yet
MEDIUM 6.7
CVE-2023-22815
Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t…
My Cloud Os
5.26.300+
HIGH 8.8
CVE-2023-22816
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b…
My Cloud Os
5.26.300+
CRITICAL 9.8
CVE-2023-34849
An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.
Ikuaios
after 3.7.1
CRITICAL 9.8
CVE-2023-26134
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails…
Git Commit Info
2.0.2+
HIGH 8.8
CVE-2023-35932
jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection happens when user input is co…
Jcvi
after 1.3.5
CRITICAL 9.8
CVE-2023-30258EPSS 94%
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTT…
Magnusbilling
after 7.3.0
HIGH 8.8
CVE-2023-30260
Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request …
Raspap
after 2.8.8
MEDIUM 5.3
CVE-2023-26429
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and …
Open Xchange Appsuite Backend
7.10.6 / 8.11.0+
HIGH 7.8
CVE-2023-24032
In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as r…
Collaboration
Patch available
CRITICAL 9.8
CVE-2023-31746
There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vuln…
Vw2100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-27836
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function …
Tl Wpa8630p Firmware
No fix yet
CRITICAL 9.8
CVE-2023-27837
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 4…
Tl Wpa8630p Firmware
No fix yet
HIGH 7.2
CVE-2023-33919EPSS 48%
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web …
Cpci85 Firmware
Patch available
HIGH 7.8
CVE-2023-26294
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
Hp Device Manager
Mitigation only
CRITICAL 9.8
CVE-2023-26295
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
Hp Device Manager
Mitigation only
HIGH 8.8
CVE-2023-26296
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
Hp Device Manager
Mitigation only
HIGH 8.8
CVE-2023-26297
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
Hp Device Manager
Mitigation only
HIGH 8.8
CVE-2023-26298
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
Hp Device Manager
Mitigation only
CRITICAL 9.8
CVE-2023-33625EPSS 33%
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxm…
Dir 600 Firmware
No fix yet
HIGH 7.5
CVE-2023-34105EPSS 9%
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, S…
Simple Realtime Server
5.0.157 / 6.0.48+
HIGH 7.5
CVE-2023-3206EPSS 19%
A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown functionality of the file /se…
Vec40g Firmware
No fix yet
HIGH 7.2
CVE-2022-38156
A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admi…
Spectralnet Narrowband Firmware
1.7.5+
HIGH 8.8
CVE-2023-35031
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, a…
Unify Openscape 4000 Assistant
Mitigation only
HIGH 8.8
CVE-2023-35032
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command inj…
Unify Openscape 4000 Assistant
Mitigation only
HIGH 8.8
CVE-2023-35033
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, a…
Unify Openscape 4000 Assistant
Mitigation only
HIGH 8.8
CVE-2023-35035
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, a…
Unify Openscape 4000 Assistant
Mitigation only
HIGH 8.8
CVE-2023-25911
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.
Ak Em100 Firmware
2.2.0.12+
HIGH 8.8
CVE-2023-34230
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In …
Snowflake Connector
2.0.18+
HIGH 8.8
CVE-2023-34232
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in …
Snowflake Connector
1.6.21+