Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2023-27770
An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_fu…
Edraw Max
No fix yet
HIGH 8.8
CVE-2022-43938EPSS 26%
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab…
Vantara Pentaho Business Analytics Server
9.3.0.2+
MEDIUM 6.3
CVE-2022-3960
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab…
Vantara Pentaho Business Analytics Server
9.3.0.2+
HIGH 7.2
CVE-2022-43769 KEVEPSS 98%
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v…
Vantara Pentaho Business Analytics Server
9.3.0.2+
CRITICAL 9.8
CVE-2023-26119
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsi…
Htmlunit
3.0.0+
CRITICAL 9.8
CVE-2023-1773
A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of…
Rockoa
Mitigation only
CRITICAL 9.8
CVE-2023-25261
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer …
Designer
Mitigation only
HIGH 7.2
CVE-2023-24835
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with admi…
Spam Sqr
2.221231+
HIGH 7.8
CVE-2022-38745
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro…
Openoffice
4.1.14+
CRITICAL 9.8
CVE-2023-28333
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploi…
Moodle
3.9.20 / 3.11.13+
HIGH 7.5
CVE-2023-24709EPSS 44%
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.
Ipr512 Firmware
No fix yet
HIGH 8.8
CVE-2023-1304
An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are nor…
Insightappsec
23.2.1 / 2023.02.01+
HIGH 8.8
CVE-2023-1306
An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead t…
Insightappsec
23.2.1 / 2023.02.01+
HIGH 7.8
CVE-2023-1250
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod…
Otrs
7.0.42 / 8.0.31+
HIGH 8.8
CVE-2023-1482
A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/…
Hkcms
No fix yet
CRITICAL 9.8
CVE-2023-0598
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an att…
Ifix
Mitigation only
CRITICAL 9.8
CVE-2023-24795
Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
Jhr N916r Firmware
after 21.11.1.1483
CRITICAL 9.8
CVE-2023-25344
An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype ano…
Swig Templates
after 2.0.4
HIGH 8.8
CVE-2023-27893
An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP manag…
Solution Manager
Mitigation only
HIGH 7.2
CVE-2023-0888
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and …
Battery Pack Sp With Wifi Firmware
after 054u000092
CRITICAL 9.8
CVE-2023-1287
An XSL template vulnerability in
ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
Enovia Live Collaboration
No fix yet
HIGH 7.8
CVE-2023-27986
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-q…
Emacs
after 28.2
CRITICAL 9.8
CVE-2023-1283
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
Qwik
0.21.0+
CRITICAL 9.8
CVE-2023-22889
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauth…
Zephyr Enterprise
after 7.15
HIGH 8.8
CVE-2023-0089
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through '…
Enterprise Protection
8.13.22 / 8.18.4+
CRITICAL 9.8
CVE-2023-0090
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code throug…
Enterprise Protection
8.13.22 / 8.18.4+
HIGH 7.8
CVE-2023-1003
A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH J…
Typora
after 1.5.5
CRITICAL 9.8
CVE-2021-36394EPSS 7%
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
Moodle
3.9.8 / 3.10.5+
CRITICAL 9.8
CVE-2023-24776
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.
Funadmin
No fix yet
HIGH 7.8
CVE-2023-26107
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization wh…
Sketchsvg
No fix yet