Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-28453
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
Npos Tesseract
No fix yet
CRITICAL 9.8
CVE-2020-7795
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
Get Npm Package Version
1.0.7+
HIGH 8.8
CVE-2022-2323EPSS 6%
Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host …
Sws12 10fpoe Firmware
1.2.0.0-3+
HIGH 8.8
CVE-2022-29558
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
Rtl819x Software Development Kit
3.6.1+
CRITICAL 9.8
CVE-2016-4991
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not prope…
Nodepdf
No fix yet
CRITICAL 9.8
CVE-2020-28435
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
Ffmpeg Sdk
No fix yet
CRITICAL 9.8
CVE-2020-28436
This affects all versions of package google-cloudstorage-commands.
Google Cloudstorage Commands
No fix yet
CRITICAL 9.8
CVE-2020-28438
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
Deferred Exec
No fix yet
CRITICAL 9.8
CVE-2020-28443
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
Sonar Wrapper
No fix yet
CRITICAL 9.8
CVE-2020-28445
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
Npm Help
No fix yet
CRITICAL 9.8
CVE-2020-28446
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
Ntesseract
0.2.9+
CRITICAL 9.8
CVE-2020-28447
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
Xopen
No fix yet
HIGH 7.8
CVE-2020-28422
All versions of package git-archive are vulnerable to Command Injection via the exports function.
Git Archive
No fix yet
CRITICAL 9.8
CVE-2022-2143EPSS 59%
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
Iview
5.7.04.6469+
CRITICAL 9.8
CVE-2022-0902EPSS 17%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma…
Rmc 100 Firmware
2105298-024 / 2105457-037+
CRITICAL 9.8
CVE-2022-31161EPSS 27%
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…
Roxy Wi
6.1.1.0+
HIGH 8.4
CVE-2022-34820
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 L…
Simatic Cp 1242 7 V2 Firmware
2.2.28 / 3.0.22+
HIGH 7.2
CVE-2022-29560
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < 2.15.1), RUGGEDCOM ROX MX5000RE (All versions < 2.15.1), RUGGEDCOM ROX RX…
Ruggedcom Rox Rx1500 Firmware
2.15.1+
CRITICAL 9.8
CVE-2022-32449EPSS 19%
TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function.…
Ex300 V2 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-34592
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows …
Wl Wn575a3 Firmware
No fix yet
HIGH 7.2
CVE-2022-28935
Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-28171EPSS 50%
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validat…
Ds A71024 Firmware
after 2.3.8-6
CRITICAL 9.8
CVE-2022-31874EPSS 19%
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
Rt N53 Firmware
No fix yet
HIGH 8.1
CVE-2022-32154
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a …
Splunk
8.2.2106 / 9.0+
CRITICAL 9.8
CVE-2022-32262
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server tha…
Sinema Remote Connect Server
3.1+
HIGH 8.8
CVE-2019-9972
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the …
Debian Linux
No fix yet
HIGH 8.8
CVE-2020-36529
A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the…
Sevone Network Performance Management
after 5.7.2.22
CRITICAL 9.8
CVE-2022-29712
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.
Librenms
Patch available
MEDIUM 6.7
CVE-2022-29256
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm in…
Sharp
0.30.5+
HIGH 8.6
CVE-2022-30321
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i…
Go Getter
after 1.5.11