Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-48895
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 …
Mitigation only
HIGH 8.8
CVE-2024-51503
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges…
Deep Security Agent
Mitigation only
HIGH 7.8
CVE-2024-10224EPSS 9%
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute …
Debian Linux
1.36+
HIGH 7.8
CVE-2024-11003EPSS 11%
Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could…
Needrestart
3.8+
HIGH 8.8
CVE-2024-52587
StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted runners. Versions of step-secur…
Patch available
HIGH 7.2
CVE-2024-9474 KEVEPSS 95%
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface …
Pan Os
10.1.14 / 10.2.12+
HIGH 7.5
CVE-2024-44759
An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arb…
Nus M9 Erp
Mitigation only
HIGH 7.5
CVE-2024-24426
Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cau…
Mitigation only
HIGH 7.5
CVE-2024-24431
A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS pack…
Open5gs
No fix yet
CRITICAL 9.9
CVE-2023-20036EPSS 13%
A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges…
Industrial Network Director
1.11.3+
HIGH 8.8
CVE-2022-20871
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance…
Asyncos
Mitigation only
MEDIUM 6.5
CVE-2022-20652
A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker …
Mitigation only
HIGH 8.8
CVE-2022-20655
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command …
Mitigation only
CRITICAL 9.8
CVE-2024-10443EPSS 28%
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePho…
Photos
1.0.2-10026 / 1.1.0-10053+
CRITICAL 9.8
CVE-2022-1884
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…
Gogs
after 0.12.7
CRITICAL 9.8
CVE-2024-11120 KEVEPSS 29%
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject a…
Gv Vs12 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-4343
A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemak…
Privategpt
0.6.0+
HIGH 8.8
CVE-2024-50852
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.
G3 Firmware
No fix yet
HIGH 8.8
CVE-2024-50853
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
G3 Firmware
No fix yet
MEDIUM 6.7
CVE-2024-32118
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager…
Fortianalyzer
7.2.6 / 7.2.8+
HIGH 8.6
CVE-2024-52010
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH feature allows an authenticated …
Patch available
HIGH 7.2
CVE-2024-11005
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…
Connect Secure
9.1 / 22.7+
HIGH 7.2
CVE-2024-11006
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…
Connect Secure
9.1 / 22.7+
HIGH 7.2
CVE-2024-11007
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…
Connect Secure
22.7+
CRITICAL 9.1
CVE-2024-46890
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent t…
Sinec Ins
1.0+
HIGH 8.0
CVE-2024-45827
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version …
Mitigation only
MEDIUM 6.8
CVE-2024-8881
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier c…
Gs1900 8 Firmware
2.90+
CRITICAL 9.8
CVE-2024-36061
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metac…
Ews356 Fit Firmware
after 1.1.30
HIGH 7.2
CVE-2024-11065
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…
Dsl6740c Firmware
Mitigation only
HIGH 7.2
CVE-2024-11066
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute ar…
Dsl6740c Firmware
Mitigation only