Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2023-31198
OS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenticated attacker with an admini…
Ac Pd Wapu Firmware
after 1.05_b04p
HIGH 8.1
CVE-2023-32548
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects…
Wps Office
Mitigation only
HIGH 7.8
CVE-2023-26210
Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet…
Fortiadc
after 7.0.5
HIGH 7.8
CVE-2023-28000
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through…
Fortiadc
after 7.0.3
HIGH 8.8
CVE-2023-34334
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can inject arbitrary shell commands,
which may l…
Megarac Sp X
12.7 / 13.5+
HIGH 8.8
CVE-2023-34343
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can inject arbitrary shell commands,
which may l…
Megarac Sp X
12.7 / 13.5+
HIGH 7.5
CVE-2023-34105EPSS 9%
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, S…
Simple Realtime Server
5.0.157 / 6.0.48+
HIGH 8.8
CVE-2023-34108
mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration…
Mailcow\
after 2023-05
HIGH 7.2
CVE-2023-33381EPSS 22%
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). Th…
Gpt 2741gnac Firmware
No fix yet
HIGH 7.8
CVE-2023-3097
A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been rated as critical. This issue affects the function setMainSo…
Kylin Software Properties
0.0.1-130+
HIGH 8.8
CVE-2023-28702
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this …
Rt Ac86u Firmware
Mitigation only
HIGH 8.8
CVE-2023-28704
Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Blueto…
Dog Camera Firmware
Mitigation only
HIGH 7.2
CVE-2022-47616
Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administra…
Coda 5310 Firmware
Mitigation only
HIGH 8.8
CVE-2023-33965
Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim…
Brook
20230606+
CRITICAL 9.8
CVE-2023-25539
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially …
Networker
19.7.0.4+
CRITICAL 9.8
CVE-2023-34152EPSS 8%
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Fedora
7.1.1-11+
MEDIUM 6.8
CVE-2022-46361
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system com…
Onewireless Network Wireless Device Manager Firmware
Mitigation only
HIGH 7.2
CVE-2023-27988
The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated …
Nas326 Firmware
5.21+
HIGH 8.8
CVE-2023-30253EPSS 79%
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Dolibarr Erp\/crm
17.0.1+
HIGH 7.8
CVE-2023-26127
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function.
**Note:**
…
N158
Mitigation only
HIGH 7.8
CVE-2023-26128
All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes be…
Keep Module Latest
No fix yet
HIGH 7.8
CVE-2023-26129
All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js fi…
Bwm Ng
No fix yet
HIGH 8.8
CVE-2023-31128
NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull…
Cookbook
0.9.19+
HIGH 7.2
CVE-2023-33617EPSS 5%
An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr para…
Fiberlink 210 Firmware
No fix yet
HIGH 8.2
CVE-2023-23693
Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged att…
Vxrail Hyperconverged Infrastructure
7.0.450+
HIGH 7.8
CVE-2023-23694
Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could p…
Vxrail Hyperconverged Infrastructure
7.0.450+
HIGH 7.2
CVE-2023-28392
Wi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and …
Ac Wapu 300 Firmware
after 1.00_b08p
HIGH 8.8
CVE-2023-28394
Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the applic…
Beekeeper Studio
3.9.9+
HIGH 8.8
CVE-2023-27514
OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior…
Sv Cpt Mc310f Firmware
8.10+
HIGH 8.8
CVE-2023-27521
OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions p…
Sv Cpt Mc310f Firmware
8.10+