Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2025-20016
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administra…
Mitigation only
CRITICAL 9.8
CVE-2025-20055
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the…
Mitigation only
CRITICAL 9.8
CVE-2025-0107EPSS 79%
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-da…
Expedition
1.2.101+
CRITICAL 9.8
CVE-2024-12847EPSS 30%
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary…
Dgn1000 Firmware
1.1.00.48+
CRITICAL 9.8
CVE-2024-57687
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote atta…
Land Record System
No fix yet
HIGH 8.8
CVE-2024-43654
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Comm…
Mitigation only
CRITICAL 9.3
CVE-2024-43655
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root
This issue aff…
Mitigation only
HIGH 8.8
CVE-2024-43656
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root
This issue aff…
Mitigation only
HIGH 8.8
CVE-2024-43657
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root
This issue aff…
Mitigation only
HIGH 8.8
CVE-2024-43649
Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root user.
This issue affects Ioch…
Mitigation only
CRITICAL 9.3
CVE-2024-43650
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Comma…
Mitigation only
CRITICAL 9.3
CVE-2024-43651
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root
This issue affe…
Mitigation only
HIGH 8.8
CVE-2024-43652
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root
This issue affe…
Mitigation only
HIGH 8.8
CVE-2024-43653
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root
This issue aff…
Mitigation only
HIGH 8.8
CVE-2024-43648
Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root user.
This issue affects Iochar…
Mitigation only
CRITICAL 9.8
CVE-2024-50603 KEVEPSS 99%
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used…
Controller
7.1.4191 / 7.2.4996+
MEDIUM 6.8
CVE-2024-11681
A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirr…
Macports
2.10.5+
HIGH 8.8
CVE-2024-13129EPSS 18%
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of …
Patch available
CRITICAL 9.8
CVE-2024-9140
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability …
Mitigation only
HIGH 7.2
CVE-2024-56137
MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-…
Maxkb
1.9.0+
HIGH 8.8
CVE-2024-12828EPSS 33%
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
Webmin
Patch available
HIGH 7.2
CVE-2024-54181
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp…
Websphere Automation
Mitigation only
MEDIUM 6.1
CVE-2024-47918
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Mitigation only
CRITICAL 9.8
CVE-2024-47919
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
No fix yet
CRITICAL 9.8
CVE-2024-12987 KEVEPSS 98%
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file …
Vigor300b Firmware
Mitigation only
HIGH 7.2
CVE-2024-12856EPSS 82%
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 …
F3x36 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-12986EPSS 33%
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown…
Vigor300b Firmware
1.5.1.5+
MEDIUM 6.3
CVE-2024-12985
A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.…
Mitigation only
HIGH 7.8
CVE-2024-53256
Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command inje…
Patch available
HIGH 7.2
CVE-2024-45721
home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An …
Mitigation only