Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2022-45095
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privile…
Emc Powerscale Onefs
9.1.0.25 / 9.2.1.18+
CRITICAL 9.8
CVE-2022-21129
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'…
Nemo Appium
0.0.9+
CRITICAL 9.8
CVE-2023-24612
The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.
Pdfbook
after 2.0.5
HIGH 7.2
CVE-2021-41231
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and…
Magento
19.4.22 / 20.0.19+
HIGH 7.2
CVE-2021-41143
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co…
Magento
19.4.22 / 20.0.19+
HIGH 8.8
CVE-2021-41144
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remot…
Magento
19.4.22 / 20.0.19+
HIGH 7.2
CVE-2021-39217
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via bl…
Magento
19.4.22 / 20.0.19+
CRITICAL 9.8
CVE-2022-25962
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Vagrant.js
Mitigation only
CRITICAL 9.8
CVE-2022-25908
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitiza…
Create Choo Electron
No fix yet
HIGH 7.8
CVE-2022-25350
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
Puppet Facter
No fix yet
HIGH 7.8
CVE-2022-21810
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.
Smartctl
No fix yet
CRITICAL 9.8
CVE-2023-22884EPSS 11%
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…
Airflow
2.5.1 / 4.0.0+
HIGH 7.5
CVE-2020-22662
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…
R310 Firmware
3.6.2.0.795+
HIGH 7.2
CVE-2023-20045
A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote…
Rv160 Vpn Router Firmware
1.0.01.04+
HIGH 7.2
CVE-2023-20026
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an aut…
Rv016 Firmware
Mitigation only
HIGH 8.8
CVE-2023-0315EPSS 98%
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
Froxlor
2.0.8+
CRITICAL 9.8
CVE-2023-22496EPSS 36%
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming c…
Netdata
1.37.0+
HIGH 8.8
CVE-2022-41955
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au…
Autolab
2.10.0+
CRITICAL 9.8
CVE-2022-21191
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sa…
Global Modules Path
3.0.0+
CRITICAL 9.1
CVE-2022-4616
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to
command injection through the network diagnosis page. This vulnerability
cou…
Dx 3021l9 Firmware
1.24+
HIGH 8.0
CVE-2020-36650
A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads …
Gry
6.0.0+
HIGH 8.8
CVE-2022-45094
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…
Sinec Ins
1.0+
CRITICAL 9.8
CVE-2022-39073
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerabi…
Mf286r Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-36642
A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical. This issue affects the function run_in_sandbox of the file applic…
Jobe
1.7.0+
CRITICAL 9.8
CVE-2023-22671
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when ca…
Ghidra
after 10.2.2
CRITICAL 9.8
CVE-2022-25923
Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input…
Exec Local Bin
1.2.0+
CRITICAL 9.8
CVE-2021-4304
A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the…
Ulcc Core
2021-02-05+
MEDIUM 6.7
CVE-2022-39086
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
Android
No fix yet
MEDIUM 6.7
CVE-2022-39087
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
Android
Mitigation only
MEDIUM 6.7
CVE-2022-39088
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
Android
Mitigation only