Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-63261
AWStats 8.0 is vulnerable to Command Injection via the open function
Debian Linux
No fix yet
HIGH 7.8
CVE-2024-10224EPSS 9%
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute …
Debian Linux
1.36+
MEDIUM 6.5
CVE-2023-51385EPSS 20%
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by a…
Debian Linux
9.6+
CRITICAL 9.8
CVE-2022-48337
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …
Debian Linux
after 28.2
HIGH 7.8
CVE-2022-4515
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified i…
Debian Linux
No fix yet
HIGH 7.8
CVE-2022-45939
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …
Debian Linux
after 28.2
HIGH 8.8
CVE-2022-3008
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…
Debian Linux
2.6.0+
HIGH 7.8
CVE-2021-45845
The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted …
Debian Linux
Patch available
HIGH 7.8
CVE-2021-45844
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
Debian Linux
Patch available
HIGH 7.0
CVE-2021-31799
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
Debian Linux
6.3.1 / 9.2.6.1+
HIGH 7.8
CVE-2020-35459
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute comma…
Debian Linux
after 4.2.1
HIGH 8.8
CVE-2020-26217EPSS 85%
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands on…
Debian Linux
1.4.14 / 5.15.14+
CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…
Debian Linux
2015.8.10 / 2015.8.13+
CRITICAL 9.8
CVE-2020-17368
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
Debian Linux
after 0.9.62
MEDIUM 5.3
CVE-2019-20807
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,…
Debian Linux
8.1.0881+
CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2011-2523EPSS 96%
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
Debian Linux
No fix yet
HIGH 8.8
CVE-2013-2024
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
Debian Linux
after 4.8.2
MEDIUM 6.8
CVE-2019-18424
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…
Debian Linux
after 4.12.1
HIGH 7.8
CVE-2019-14744
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This r…
Debian Linux
5.61.0+
HIGH 7.8
CVE-2019-13638
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…
Debian Linux
Patch available
HIGH 7.8
CVE-2019-13574EPSS 8%
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input…
Debian Linux
4.9.4+
CRITICAL 9.8
CVE-2019-11627
gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
Debian Linux
2.10+
HIGH 7.8
CVE-2018-16741
An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to p…
Debian Linux
1.2.1+
HIGH 7.8
CVE-2018-10900EPSS 5%
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can b…
Debian Linux
1.2.6+
HIGH 7.8
CVE-2018-3836
An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argumen…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2018-7440
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…
Debian Linux
after 1.75.3
MEDIUM 6.8
CVE-2018-6791
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $(…
Debian Linux
5.12.0+
HIGH 7.8
CVE-2017-15108
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the …
Debian Linux
after 0.17.0
CRITICAL 9.8
CVE-2017-1000487EPSS 6%
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
Debian Linux
3.0.16+