Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2024-25579
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbi…
Mitigation only
HIGH 8.8
CVE-2023-25925
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands…
Security Guardium Key Lifecycle Manager
4.1.1.7+
HIGH 7.3
CVE-2024-1683
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay hos…
Identity Exposure
3.59.4+
HIGH 8.1
CVE-2023-51450
baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of bas…
Basercms
5.0.9+
HIGH 8.0
CVE-2024-25851
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.
Wf2780 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-1212 KEVEPSS 95%
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Loadmaster
7.2.48.10 / 7.2.54.8+
HIGH 7.2
CVE-2023-6398
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1,…
Atp100 Firmware
5.37+
HIGH 7.2
CVE-2024-1297
Loomio version 2.22.0 allows executing arbitrary commands on the server.
This is possible because the application is vulnerable to OS Command Inject…
Loomio
Patch available
HIGH 8.8
CVE-2023-6260
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command In…
Acs100 Firmware
6.2.4.3+
CRITICAL 9.8
CVE-2024-25626
Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture…
Yocto
3.1.31 / 4.0.16+
HIGH 7.8
CVE-2022-48624
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Less
606+
HIGH 7.5
CVE-2024-25468
An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncW…
X5000r Firmware
No fix yet
CRITICAL 9.8
CVE-2024-22426
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potent…
Recoverpoint For Virtual Machines
Mitigation only
CRITICAL 9.1
CVE-2024-20720
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command…
Commerce
Mitigation only
CRITICAL 9.8
CVE-2023-32462
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remot…
Smartfabric Os10
10.5.2.12 / 10.5.3.8+
CRITICAL 9.8
CVE-2024-26260
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inj…
Oaklouds Organization 2.0
188 / 1051+
HIGH 7.2
CVE-2024-1367
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application cou…
Security Center
6.3.0+
MEDIUM 6.7
CVE-2024-21782
BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 8.8
CVE-2024-23789
Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to exec…
Jh Rvb1 Firmware
Mitigation only
HIGH 8.8
CVE-2024-23812
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when cr…
Sinec Nms
2.0+
HIGH 7.2
CVE-2024-22445
Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker co…
Powerprotect Data Manager
after 19.15
MEDIUM 6.3
CVE-2024-22132
SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behavio…
Ides Ecc
Mitigation only
HIGH 8.3
CVE-2023-47218EPSS 90%
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…
Qts
5.1.5.2645+
MEDIUM 5.8
CVE-2023-50358EPSS 14%
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…
Qts
4.2.6 / 4.3.3.2644+
HIGH 7.8
CVE-2024-22227
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially …
Unity Operating Environment
5.4.0.0.5.094+
HIGH 7.8
CVE-2024-22228
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could pot…
Unity Operating Environment
5.4.0.0.5.094+
HIGH 7.8
CVE-2024-22222
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user wit…
Unity Operating Environment
5.4.0.0.5.094+
HIGH 7.8
CVE-2024-22223
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with lo…
Unity Operating Environment
5.4.0.0.5.094+
HIGH 7.8
CVE-2024-22224
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially…
Unity Operating Environment
5.4.0.0.5.094+
HIGH 7.8
CVE-2024-22225
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could p…
Unity Operating Environment
5.4.0.0.5.094+