Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-30898
An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be …
Airflow
3.2.0+
HIGH 8.8
CVE-2026-35682
Anviz CX2 Lite is vulnerable to an authenticated command injection via a
filename parameter that enables arbitrary command execution (e.g.,
startin…
Cx2 Lite Firmware
Mitigation only
MEDIUM 6.7
CVE-2026-21709
A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
Mitigation only
CRITICAL 9.8
CVE-2026-41153
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
Junie
252.549.29+
HIGH 7.2
CVE-2026-6483EPSS 14%
A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. …
Mitigation only
MEDIUM 6.7
CVE-2026-23779
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.50+
HIGH 7.2
CVE-2026-23778
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.50+
CRITICAL 9.9
CVE-2026-20186EPSS 6%
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…
Identity Services Engine
3.2.0+
CRITICAL 9.9
CVE-2026-20147EPSS 12%
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…
Identity Services Engine Passive Identity Connector
3.1.0+
HIGH 8.3
CVE-2026-30461
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.ph…
Fuel Cms
No fix yet
HIGH 8.0
CVE-2026-30615
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf proces…
Mitigation only
HIGH 7.3
CVE-2026-30616
Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network re…
Mitigation only
HIGH 8.6
CVE-2026-30617
LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attack…
Mitigation only
HIGH 8.6
CVE-2026-30624
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to de…
Agent Zero
Mitigation only
CRITICAL 9.8
CVE-2026-30625
Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M…
Patch available
HIGH 8.4
CVE-2024-53412
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote…
Mitigation only
HIGH 7.8
CVE-2026-32183
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execu…
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 6.5
CVE-2026-23653
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att…
Github Copilot Chat
0.37.3+
HIGH 7.1
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.…
Patch available
MEDIUM 5.3
CVE-2026-6219
A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of…
No fix yet
CRITICAL 9.8
CVE-2026-6195EPSS 14%
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the fil…
Mitigation only
HIGH 7.3
CVE-2026-6158
A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of t…
Mitigation only
CRITICAL 9.8
CVE-2026-6155
A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the…
Mitigation only
CRITICAL 9.8
CVE-2026-6156
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cst…
Mitigation only
CRITICAL 9.8
CVE-2026-6154
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/…
Mitigation only
CRITICAL 9.8
CVE-2026-6139
A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi…
Mitigation only
CRITICAL 9.8
CVE-2026-6140
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of …
Mitigation only
MEDIUM 6.3
CVE-2026-6141
A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/To…
Patch available
CRITICAL 9.8
CVE-2026-6138
A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.…
Mitigation only
CRITICAL 9.8
CVE-2026-6131
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-…
Mitigation only