Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-48586
A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it …
Sl1
after 11.1.2
HIGH 8.8
CVE-2022-48580
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and…
Sl1
after 11.1.2
HIGH 8.8
CVE-2022-48581
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes…
Sl1
after 11.1.2
HIGH 7.2
CVE-2023-38208
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Speci…
Commerce
2.4.4+
HIGH 8.8
CVE-2023-37861
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions wit…
Wp 6070 Wvps Firmware
4.0.10+
HIGH 7.2
CVE-2023-37863
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP re…
Wp 6070 Wvps Firmware
4.0.10+
HIGH 8.8
CVE-2023-37569EPSS 34%
This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated …
Emagic Data Center Management
after 6.0
HIGH 8.8
CVE-2023-3570
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE reques…
Wp 6070 Wvps Firmware
4.0.10+
HIGH 8.8
CVE-2023-3571
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated…
Wp 6070 Wvps Firmware
4.0.10+
CRITICAL 10.0
CVE-2023-3572
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP …
Wp 6070 Wvps Firmware
4.0.10+
HIGH 8.8
CVE-2023-3573
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP…
Wp 6070 Wvps Firmware
4.0.10+
CRITICAL 9.8
CVE-2023-38692
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the…
Cloudexplorer Lite
1.3.1+
CRITICAL 9.8
CVE-2023-33374
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands f…
Connected Io
after 2.1.0
CRITICAL 9.8
CVE-2023-33377
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling a…
Connected Io
after 2.1.0
HIGH 8.8
CVE-2023-33364
An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on…
Biostar 2
2.9.1+
HIGH 8.8
CVE-2023-21411
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for
arbitrary code execution.
License Plate Verifier
after 2.8.3
HIGH 8.8
CVE-2023-21410
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for
arbitrary code execution.
License Plate Verifier
after 2.8.3
CRITICAL 9.8
CVE-2023-26317
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external…
Xiaomi Router Firmware
2023.2+
HIGH 7.8
CVE-2023-31425
A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local a…
Fabric Operating System
Mitigation only
HIGH 7.8
CVE-2023-4033
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
Mlflow
2.6.0+
CRITICAL 9.8
CVE-2023-35861
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to injec…
H12dst B Firmware
03.10.35+
HIGH 8.8
CVE-2023-35019
IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by send…
Security Verify Governance
Mitigation only
CRITICAL 9.8
CVE-2023-37213
Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'
Synergy\/a Firmware
3015.1+
CRITICAL 9.8
CVE-2023-3974
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.
Drawio
21.4.0+
CRITICAL 9.8
CVE-2023-3975
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
Drawio
21.5.0+
CRITICAL 9.8
CVE-2023-38673
PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.
Paddlepaddle
2.5.0+
HIGH 7.2
CVE-2023-38056
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows …
Otrs
7.0.45 / 8.0.35+
CRITICAL 10.0
CVE-2023-37903
vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esc…
Vm2
after 3.9.19
CRITICAL 9.8
CVE-2023-37292
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modul…
Isherlock
4.5-174 / 5.5-174+
CRITICAL 9.8
CVE-2023-36670
A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as r…
Ngc Indoor Unit Firmware
Mitigation only