Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-36767
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
Tinyfiledialogs
3.8.0+
CRITICAL 9.8
CVE-2023-5843
The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load…
Ads By Datafeedr.com
after 1.1.3
HIGH 7.8
CVE-2023-44141
Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file.
Inkdrop
5.6.0+
HIGH 7.2
CVE-2023-46865EPSS 20%
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code i…
Crater
after 6.0.6
HIGH 7.8
CVE-2021-33635
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
Isula
Patch available
HIGH 7.8
CVE-2021-33636
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
Isula
Patch available
CRITICAL 9.8
CVE-2023-46509
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
Solarview Compact Firmware
after 6.0
HIGH 8.8
CVE-2023-46816
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified …
Sugarcrm
12.0.4+
HIGH 7.2
CVE-2023-46818EPSS 16%
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_lange…
Ispconfig
3.2.11+
HIGH 7.8
CVE-2023-43352
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
Cms Made Simple
No fix yet
HIGH 7.8
CVE-2023-5623
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…
Nessus Network Monitor
6.3.0+
HIGH 8.8
CVE-2023-5044EPSS 57%
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
Ingress Nginx
1.9.0+
CRITICAL 9.8
CVE-2023-46010
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
Seacms
after 12.9
HIGH 8.8
CVE-2023-37909
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to ve…
Xwiki
14.10.8+
CRITICAL 9.8
CVE-2023-30912
A remote code execution issue exists in HPE OneView.
Oneview
8.60.00+
HIGH 7.8
CVE-2023-28793
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Clie…
Client Connector
1.3.1.6+
HIGH 7.8
CVE-2023-28796
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler…
Client Connector
1.3.1.6+
HIGH 8.8
CVE-2023-46055
An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping funct…
Photon
No fix yet
HIGH 7.8
CVE-2023-41898
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL …
Home Assistant Companion
2023.9.2+
CRITICAL 9.8
CVE-2023-30131
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified …
Easyinstall
No fix yet
CRITICAL 9.8
CVE-2023-46042EPSS 23%
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().
Getsimplecms
No fix yet
CRITICAL 9.8
CVE-2023-41630
eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.
Esst Monitoring
after 2.147.1
CRITICAL 9.6
CVE-2023-45144
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user …
Oauth Identity
1.6+
CRITICAL 9.8
CVE-2023-29453
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, …
Zabbix Agent2
5.0.35 / 6.0.18+
HIGH 8.8
CVE-2023-43661EPSS 47%
Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to e…
Cachet
2.4+
HIGH 7.2
CVE-2023-36789
Skype for Business Remote Code Execution Vulnerability
Skype For Business Server
Patch available
HIGH 7.8
CVE-2023-36718
Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20232 / 10.0.14393.6351+
HIGH 7.8
CVE-2023-36702
Microsoft DirectMusic Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20232 / 10.0.14393.6351+
HIGH 7.3
CVE-2023-36589
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Windows 10
10.0.10240.20232 / 10.0.14393.6351+
HIGH 7.3
CVE-2023-36591
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Windows 10
10.0.10240.20232 / 10.0.14393.6351+