Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-23596EPSS 15%
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted u…
Nginx Proxy Manager
after 2.9.19
HIGH 7.2
CVE-2023-20007
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could all…
Rv340 Firmware
1.0.03.29+
HIGH 8.8
CVE-2022-20964EPSS 31%
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbit…
Identity Services Engine
2.6.0+
CRITICAL 9.8
CVE-2022-46476EPSS 41%
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
Dir 859 A1 Firmware
No fix yet
HIGH 8.8
CVE-2023-0164
OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the applic…
Orangescrum
No fix yet
HIGH 7.2
CVE-2022-47911
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to t…
Real Time Location System Studio
after 2.6.2
HIGH 7.2
CVE-2022-43483
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to t…
Real Time Location System Studio
after 2.6.2
HIGH 8.0
CVE-2022-2251
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows …
Runner
15.3.5 / 15.4.4+
CRITICAL 9.8
CVE-2022-47853
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root sh…
A7100ru Firmware
No fix yet
CRITICAL 9.8
CVE-2023-22279
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer Mobile…
Maho Pbx Netdevancer Firmware
1.11.00+
HIGH 7.2
CVE-2023-22280
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer Mobile…
Maho Pbx Netdevancer Firmware
1.11.00+
HIGH 8.0
CVE-2023-22304
OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker who can a…
Pix Rt100 Firmware
Mitigation only
HIGH 8.8
CVE-2022-41955
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au…
Autolab
2.10.0+
CRITICAL 9.8
CVE-2022-21191
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sa…
Global Modules Path
3.0.0+
HIGH 8.8
CVE-2022-42289
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi…
Dgx A100 Firmware
00.19.07+
HIGH 8.8
CVE-2022-42290
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi…
Dgx A100 Firmware
00.19.07+
HIGH 8.8
CVE-2022-42279
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code executi…
Dgx A100 Firmware
00.19.07+
HIGH 7.2
CVE-2023-22598
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW…
Inrouter302 Firmware
2.3.0.r5542 / 3.5.56+
HIGH 8.8
CVE-2022-43390
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker t…
Lte7480 M804 Firmware
1.00 / 1.15+
CRITICAL 9.8
CVE-2022-48252
The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.
Pi.alert
No fix yet
HIGH 7.2
CVE-2022-43971
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_set…
Wumc710 Firmware
1.0.02+
HIGH 7.2
CVE-2022-43973
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI functio…
Wrt54gl Firmware
after 4.30.18.006
HIGH 7.8
CVE-2022-36926
Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this…
Rooms
5.11.3+
CRITICAL 9.8
CVE-2022-25890
All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
Wifey
No fix yet
HIGH 8.8
CVE-2022-44149EPSS 64%
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON…
Amp300 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-25923
Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input…
Exec Local Bin
1.2.0+
CRITICAL 9.8
CVE-2022-44877 KEVEPSS 100%
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via s…
Webpanel
0.9.8.1147+
HIGH 8.8
CVE-2022-43536
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…
Clearpass Policy Manager
6.9.12 / 6.10.7+
HIGH 7.2
CVE-2022-43537
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…
Clearpass Policy Manager
6.9.12 / 6.10.7+
HIGH 7.2
CVE-2022-43538
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the unde…
Clearpass Policy Manager
6.9.12 / 6.10.7+