Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-2868 KEVEPSS 87%
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3…
Email Security Gateway 300 Firmware
after 9.2.0.006
HIGH 7.2
CVE-2023-31740
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, …
E2000 Firmware
No fix yet
HIGH 7.2
CVE-2023-31741
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, …
E2000 Firmware
No fix yet
HIGH 8.8
CVE-2023-31996
Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test fu…
Ane L6012r Firmware
1.41.03+
HIGH 7.2
CVE-2023-31742EPSS 9%
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privi…
Wrt54gl Firmware
No fix yet
CRITICAL 9.8
CVE-2023-33294
An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST reques…
Kaios
No fix yet
HIGH 8.8
CVE-2023-33235
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be ex…
Mxsecurity
Patch available
HIGH 7.8
CVE-2023-32700
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because lu…
Luatex
1.16.2 / 23.5+
CRITICAL 9.8
CVE-2023-31729
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
A3300r Firmware
Mitigation only
HIGH 7.8
CVE-2023-2491
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el ca…
Enterprise Linux
Mitigation only
HIGH 8.8
CVE-2023-31700
TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd.
Tl Wpa4530 Kit Firmware
No fix yet
HIGH 8.8
CVE-2023-31701
TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove.
Tl Wpa4530 Kit Firmware
No fix yet
HIGH 8.8
CVE-2023-31208
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary live…
Checkmk
2.0.0+
CRITICAL 9.8
CVE-2023-31856
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers …
Cp300\+ Firmware
No fix yet
CRITICAL 9.8
CVE-2023-31986EPSS 8%
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN funct…
Br 6428ns Firmware
No fix yet
CRITICAL 9.8
CVE-2023-31983EPSS 25%
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function …
Br 6428ns Firmware
No fix yet
HIGH 8.8
CVE-2023-32073EPSS 6%
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.j…
Avideo
after 12.4
MEDIUM 6.3
CVE-2023-2682
A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/…
Caton Live
after 2023-04-26
CRITICAL 9.8
CVE-2023-31985EPSS 8%
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept f…
Br 6428ns Firmware
No fix yet
HIGH 8.8
CVE-2023-31528
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.
Cx2l Firmware
No fix yet
HIGH 8.8
CVE-2023-31529
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.
Cx2l Firmware
No fix yet
HIGH 8.8
CVE-2023-31530
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.
Cx2l Firmware
No fix yet
HIGH 8.8
CVE-2023-31531
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.
Cx2l Firmware
No fix yet
CRITICAL 9.8
CVE-2023-24540
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character s…
Go
1.19.9 / 1.20.4+
HIGH 8.8
CVE-2023-2647EPSS 7%
A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroo…
E Office
No fix yet
HIGH 8.8
CVE-2023-2649EPSS 10%
A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/at…
Ac23 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-29842
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the…
My Cloud Os
5.26.119+
CRITICAL 9.8
CVE-2023-30353
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
Cp3 Firmware
Mitigation only
HIGH 7.5
CVE-2023-31476
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almo…
Gl Mv1000w Firmware
after 3.215
HIGH 7.2
CVE-2023-28832
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2…
6gk1411 1ac00 Firmware
Patch available