Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-32728
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f…
Zabbix Agent2
after 6.4.8
CRITICAL 9.8
CVE-2023-6899
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of t…
Dashmachine
No fix yet
CRITICAL 9.8
CVE-2023-6886
A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the componen…
Wangmarket
Mitigation only
CRITICAL 9.8
CVE-2023-6851
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the fil…
Kodexplorer
4.52.01+
HIGH 8.8
CVE-2023-50723
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wi…
Xwiki
14.10.5 / 15.5.2+
HIGH 8.8
CVE-2023-50721EPSS 79%
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration inte…
Xwiki
14.10.5 / 15.5.2+
MEDIUM 5.7
CVE-2023-5512
An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versi…
GitLab
16.4.4 / 16.5.4+
MEDIUM 6.5
CVE-2023-6051
An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starti…
GitLab
16.4.4 / 16.5.4+
CRITICAL 9.8
CVE-2023-6553EPSS 98%
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup…
Backup Migration
after 1.3.7
CRITICAL 9.8
CVE-2023-48390
Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and acce…
Easylog Web\+ Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-48085EPSS 76%
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.
Nagios Xi
5.11.3+
CRITICAL 9.8
CVE-2023-43364
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
Searchor
2.4.2+
HIGH 8.8
CVE-2023-42890
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2,…
Safari
10.2 / 14.2+
HIGH 8.8
CVE-2023-5500
This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full con…
Frauscher Diagnostic System 102
2.10.2+
HIGH 8.2
CVE-2023-43301
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access toke…
Line
No fix yet
HIGH 7.8
CVE-2023-6288
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environmen…
Remote Desktop Manager
2023.3.10.2+
CRITICAL 9.8
CVE-2023-49070EPSS 95%
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present.
This issue affects Apache OFBiz: before 18.12.10.
Us…
Ofbiz
18.12.10+
HIGH 8.8
CVE-2023-5762
The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execut…
Filr
1.2.3.6+
HIGH 8.8
CVE-2023-49093
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpag…
Htmlunit
3.9.0+
CRITICAL 9.1
CVE-2023-44382
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms…
October
3.4.15+
HIGH 7.5
CVE-2023-5226
An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting fro…
GitLab
16.4.3 / 16.5.3+
CRITICAL 9.8
CVE-2022-42541
Remote code execution
Android
No fix yet
CRITICAL 9.8
CVE-2023-49313
A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected …
Xmachoviewer
No fix yet
HIGH 7.8
CVE-2023-49314
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through …
Desktop
Mitigation only
CRITICAL 9.8
CVE-2023-46480
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the ind…
Owncast
Mitigation only
CRITICAL 9.8
CVE-2023-5604
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configu…
Asgaros Forum
2.7.1+
HIGH 7.2
CVE-2021-22150
It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, th…
Kibana
7.14.1+
CRITICAL 9.8
CVE-2023-48699
fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker…
Fastbots
0.1.5+
CRITICAL 9.8
CVE-2023-6248
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex…
Syrus 4g Iot Telematics Gateway Firmware
Mitigation only
HIGH 7.8
CVE-2023-48192
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
A3700r Firmware
No fix yet