Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-48337
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …
Debian Linux
after 28.2
HIGH 7.5
CVE-2022-46303
Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana…
Checkmk
Mitigation only
HIGH 8.8
CVE-2023-23779
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.…
Fortiweb
after 6.3.19
HIGH 7.8
CVE-2022-27482
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 …
Fortiadc
6.2.4+
HIGH 7.2
CVE-2022-27489
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.…
Fortiextender Firmware
3.2.4 / 3.3.3+
HIGH 8.8
CVE-2022-30303
An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through…
Fortiweb
6.3.20+
HIGH 8.8
CVE-2022-33869
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5…
Fortiwan
4.5.10+
HIGH 8.8
CVE-2023-0861EPSS 29%
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authe…
Netmodule Router Software
4.3.0.119 / 4.4.0.118+
HIGH 8.8
CVE-2023-0830EPSS 21%
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation lead…
Easynas
No fix yet
HIGH 8.8
CVE-2023-20076
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root …
Ic3000 Industrial Compute Gateway
1.4.2 / 1.10.0.1+
HIGH 8.8
CVE-2022-45104
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low priv…
Evasa Provider Virtual Appliance
9.2.3.6 / 9.2.4.15+
HIGH 7.2
CVE-2022-34447
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker wit…
Powerpath Management Appliance
Mitigation only
HIGH 7.0
CVE-2023-24816
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python prog…
Ipython
8.10.0+
HIGH 8.8
CVE-2022-46649
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell comman…
Aleos
after 4.16.0
CRITICAL 9.8
CVE-2022-45699EPSS 77%
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary comma…
Ecu R Firmware
No fix yet
CRITICAL 9.8
CVE-2022-43550
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which cou…
Jitsi
2022-09-14+
HIGH 8.8
CVE-2022-45768EPSS 29%
Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via…
Br 6428ns Firmware
No fix yet
CRITICAL 9.8
CVE-2022-31249
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote …
Wrangler
0.7.4 / 0.8.5+
MEDIUM 6.8
CVE-2022-43758
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for …
Rancher
2.5.17 / 2.6.10+
HIGH 7.8
CVE-2023-22643
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux E…
Libzypp Plugin Appdata
1.0.1+
HIGH 7.2
CVE-2022-38547
A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series f…
Atp100 Firmware
after 5.32
HIGH 7.8
CVE-2022-25855
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
Create Choo App3
No fix yet
HIGH 7.8
CVE-2022-25853
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.
Semver Tags
No fix yet
HIGH 8.8
CVE-2022-46552EPSS 11%
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist paramete…
Dir 846 Firmware
No fix yet
CRITICAL 9.8
CVE-2023-23076EPSS 74%
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
Manageengine Supportcenter Plus
Mitigation only
HIGH 8.8
CVE-2023-23692
Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially exploit th…
Emc Data Domain Os
6.2.1.90 / 7.7.3+
HIGH 7.8
CVE-2022-25916
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' functi…
Mt7688 Wiscan
0.8.3+
HIGH 7.8
CVE-2022-25906
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being emplo…
Is Http2
No fix yet
CRITICAL 9.8
CVE-2022-21129
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'…
Nemo Appium
0.0.9+
CRITICAL 9.8
CVE-2022-42484EPSS 6%
An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lea…
Freshtomato
No fix yet