Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2024-25082
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Debian Linux
after 20230101
HIGH 7.8
CVE-2022-42906
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration…
Debian Linux
1.3.2+
HIGH 8.8
CVE-2022-3008
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…
Debian Linux
2.6.0+
HIGH 8.8
CVE-2019-9972
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the …
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2021-43113EPSS 5%
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost…
Debian Linux
7.1.17+
CRITICAL 9.8
CVE-2021-38173
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize…
Debian Linux
0.31.2+
HIGH 8.8
CVE-2015-1877
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which all…
Debian Linux
Patch available
HIGH 7.8
CVE-2019-14868
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypas…
Debian Linux
10.15.5+
MEDIUM 6.5
CVE-2019-12921EPSS 8%
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of Translate…
Debian Linux
1.3.32+
CRITICAL 9.8
CVE-2019-17361EPSS 15%
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat…
Debian Linux
after 2019.2.0
CRITICAL 9.8
CVE-2019-1010174
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac…
Debian Linux
2.3.4+
HIGH 7.8
CVE-2019-1000018
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p…
Debian Linux
No fix yet
HIGH 7.8
CVE-2015-8971
Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2015-0857EPSS 5%
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…
Debian Linux
Mitigation only
HIGH 8.8
CVE-2016-2056EPSS 55%
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the …
Debian Linux
Patch available
HIGH 7.5
CVE-2014-7209
run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metach…
Mime Support
after 3.52-1
HIGH 7.5
CVE-2014-8990EPSS 5%
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Debian Linux
after 2.1.5
HIGH 7.8
CVE-2010-4345 KEVEPSS 18%
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration …
Debian Linux
after 4.72