Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2022-36786
DLINK - DSL-224 Post-auth RCE.
DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc AP…
Dsl 224 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-40881EPSS 29%
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
Solarview Compact Firmware
No fix yet
CRITICAL 9.8
CVE-2022-43781EPSS 98%
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control th…
Bitbucket
7.6.19 / 7.17.12+
CRITICAL 9.8
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …
Infosphere Information Server
Patch available
MEDIUM 6.7
CVE-2022-20934
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to e…
Secure Firewall Threat Defense
after 7.0.4
HIGH 7.2
CVE-2022-20925
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker…
Secure Firewall Management Center
Mitigation only
HIGH 8.8
CVE-2022-20926
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker…
Secure Firewall Management Center
Mitigation only
CRITICAL 9.8
CVE-2022-45063
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within …
Fedora
375+
CRITICAL 9.8
CVE-2022-43109
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows…
Dir 823g Firmware
No fix yet
CRITICAL 9.8
CVE-2022-37425
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remot…
Opennebula
6.4.2+
CRITICAL 9.8
CVE-2022-43367EPSS 5%
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.
Ew9 Firmware
No fix yet
HIGH 7.5
CVE-2022-35265
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…
R1510 Firmware
No fix yet
HIGH 7.5
CVE-2022-35266
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…
R1510 Firmware
No fix yet
HIGH 7.5
CVE-2022-35267
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…
R1510 Firmware
No fix yet
HIGH 7.5
CVE-2022-35269
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…
R1510 Firmware
No fix yet
HIGH 7.5
CVE-2022-35270
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…
R1510 Firmware
No fix yet
HIGH 7.5
CVE-2022-35271
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…
R1510 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-32765
An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafte…
R1510 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-26727
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker…
Iac Ast2500a Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-26728
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arb…
Iac Ast2500a Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-26729
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker t…
Iac Ast2500a Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-26731
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticate…
Iac Ast2500a Firmware
Mitigation only
HIGH 7.2
CVE-2022-41617
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is…
Big Ip Advanced Web Application Firewall
13.1.5.1 / 14.1.5.1+
CRITICAL 9.8
CVE-2016-20017 KEVEPSS 65%
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016…
Dsl 2750b Firmware
1.05+
HIGH 8.8
CVE-2022-42156
D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetwo…
Covr 1203 Firmware
No fix yet
HIGH 8.8
CVE-2022-42160
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNT…
Covr 1203 Firmware
No fix yet
HIGH 8.8
CVE-2022-42161
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTrig…
Covr 1203 Firmware
No fix yet
HIGH 7.8
CVE-2022-42906
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration…
Debian Linux
1.3.2+
CRITICAL 9.8
CVE-2022-42897
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of th…
Arrayos Ag
after 9.4.0.469
HIGH 8.2
CVE-2022-34432
Dell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowing deletion…
Hybrid Client
1.8+