Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-1412
A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown funct…
Operation And Maintenance Security Management System
after 3.0.12
HIGH 8.8
CVE-2026-0779
ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…
8180 Ip Audio Alerter Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-24132
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions
7.19.0 and below and 8.0.0-rc.0 th…
Orval
7.20.0 / 8.0.3+
HIGH 7.5
CVE-2026-21520
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …
Copilot Studio
Mitigation only
CRITICAL 9.8
CVE-2026-1324EPSS 6%
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon…
Operation And Maintenance Security Management System
after 3.0.12
HIGH 8.8
CVE-2026-1326
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cste…
Nr1800x Firmware
No fix yet
HIGH 8.8
CVE-2026-1327
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /c…
Nr1800x Firmware
No fix yet
MEDIUM 5.9
CVE-2025-15366
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containi…
Patch available
MEDIUM 5.9
CVE-2025-15367
The poplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects commands
containin…
Patch available
CRITICAL 9.8
CVE-2026-23947
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul…
Orval
7.19.0 / 8.0.2+
HIGH 7.3
CVE-2026-1192EPSS 6%
A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of th…
Online Store Management System
No fix yet
HIGH 8.8
CVE-2026-1150
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.c…
Lr350 Firmware
No fix yet
HIGH 8.8
CVE-2026-1149
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.…
Lr350 Firmware
No fix yet
CRITICAL 9.8
CVE-2026-1125EPSS 15%
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings.…
Dir 823x Firmware
Mitigation only
HIGH 8.8
CVE-2026-1066EPSS 5%
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the co…
Kodbox
after 1.61.10
CRITICAL 9.8
CVE-2025-60021EPSS 25%
Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …
Brpc
1.15.0+
CRITICAL 9.8
CVE-2026-0975
Delta Electronics DIAView has Command Injection vulnerability.
Diaview
4.4.0+
CRITICAL 9.8
CVE-2026-22864
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning…
Deno
2.5.6+
CRITICAL 9.8
CVE-2026-22708
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…
Cursor
2.3+
HIGH 7.2
CVE-2025-37176
A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially af…
Arubaos
8.10.0.21 / 8.13.1.1+
CRITICAL 9.3
CVE-2026-22755EPSS 20%
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365…
Mitigation only
CRITICAL 9.8
CVE-2026-22785
orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation l…
Orval
7.18.0+
CRITICAL 9.8
CVE-2025-15502EPSS 6%
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro…
Operation And Maintenance Security Management System
after 3.0.8
HIGH 8.8
CVE-2026-22688
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injec…
Weknora
0.2.5+
HIGH 7.2
CVE-2026-22601
OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…
Openproject
16.6.2+
CRITICAL 9.8
CVE-2025-15501EPSS 6%
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th…
Operation And Maintenance Security Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15500EPSS 6%
A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file …
Operation And Maintenance Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15499EPSS 5%
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o…
Operation And Maintenance Management System
after 3.0.8
MEDIUM 6.5
CVE-2025-66715
A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.
Odis
after 1.8.4
CRITICAL 9.8
CVE-2025-69542EPSS 9%
A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease r…
Dir 895la1 Firmware
Mitigation only