Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-50757
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerab…
Wl Wn535k3 Firmware
No fix yet
MEDIUM 6.5
CVE-2024-48705
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while reset…
Wl Wn531p3 Firmware
No fix yet
HIGH 7.8
CVE-2025-58178
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injec…
Patch available
MEDIUM 6.2
CVE-2025-9769EPSS 26%
A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulati…
Di 7400g\+ Firmware
No fix yet
CRITICAL 9.8
CVE-2025-9752EPSS 16%
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component …
Dir 852 Firmware
Mitigation only
HIGH 7.2
CVE-2025-9745EPSS 10%
A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.a…
Di 500wf Firmware
No fix yet
CRITICAL 9.8
CVE-2025-9727
A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulatio…
Dir 816l Firmware
Mitigation only
HIGH 8.4
CVE-2025-44015
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit th…
Hybriddesk Station
4.2.18+
HIGH 8.8
CVE-2025-30264
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they…
Qts
Mitigation only
HIGH 7.2
CVE-2025-29887
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then expl…
Qurouter
Mitigation only
MEDIUM 6.3
CVE-2025-9654
A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simp…
Patch available
CRITICAL 9.8
CVE-2025-9603EPSS 8%
A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command…
Tlr 2005ksh Firmware
Mitigation only
HIGH 8.8
CVE-2025-9585EPSS 5%
A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipula…
Cf N1 Firmware
No fix yet
HIGH 8.8
CVE-2025-9586EPSS 8%
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. S…
Cf N1 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-9582EPSS 5%
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argum…
Cf N1 Firmware
Mitigation only
HIGH 8.8
CVE-2025-9583EPSS 5%
A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The m…
Cf N1 Firmware
No fix yet
HIGH 8.8
CVE-2025-9584EPSS 8%
A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manip…
Cf N1 Firmware
No fix yet
HIGH 8.8
CVE-2025-9579EPSS 7%
A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the compo…
Bl X26 Firmware
No fix yet
HIGH 8.8
CVE-2025-9580EPSS 7%
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the compone…
Bl X26 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-9581EPSS 5%
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of t…
Cf N1 Firmware
Mitigation only
HIGH 8.8
CVE-2025-9575EPSS 8%
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. …
Re6250 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-50428
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to i…
Raspap Webgui
after 3.3.2
CRITICAL 9.1
CVE-2025-50989EPSS 8%
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). …
Opnsense
25.1.8+
HIGH 7.2
CVE-2025-9528EPSS 48%
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand.…
E1700 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-9424EPSS 18%
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch…
Ws7204 A Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-50722
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component
Sparkshop
Mitigation only
HIGH 7.2
CVE-2025-29523
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.
Dsl 7740c Firmware
No fix yet
MEDIUM 6.5
CVE-2025-44179
Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input validation…
Mitigation only
MEDIUM 6.5
CVE-2025-29522
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.
Dsl 7740c Firmware
No fix yet
MEDIUM 5.3
CVE-2025-29519
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbit…
Dsl 7740c Firmware
No fix yet