Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-16763
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js …
No fix yet
CRITICAL 9.4
CVE-2026-47670
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid …
No fix yet
MEDIUM 5.3
CVE-2026-16733
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js…
No fix yet
MEDIUM 5.3
CVE-2026-16735
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file in…
No fix yet
MEDIUM 5.3
CVE-2026-16631
A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component packa…
No fix yet
MEDIUM 5.3
CVE-2026-16630
A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the…
No fix yet
MEDIUM 5.3
CVE-2026-16629
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/loc…
No fix yet
MEDIUM 5.3
CVE-2026-16628
A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin En…
No fix yet
MEDIUM 5.5
CVE-2026-16492
A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/g…
No fix yet
MEDIUM 5.0
CVE-2026-16488
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/conf…
No fix yet
MEDIUM 5.3
CVE-2026-16489
A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the comp…
No fix yet
HIGH 7.5
CVE-2026-47690
MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbb…
No fix yet
CRITICAL 9.3
CVE-2026-47708
MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` A…
No fix yet
HIGH 7.2
CVE-2026-44879
A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injec…
No fix yet
MEDIUM 6.3
CVE-2026-16448
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…
No fix yet
MEDIUM 5.0
CVE-2026-16133
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executi…
No fix yet
HIGH 8.0
CVE-2025-71392
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command.…
Surrealdb
2.0.5 / 2.1.5+
CRITICAL 9.1
CVE-2026-52199
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
Mitigation only
CRITICAL 9.8
CVE-2026-30623EPSS 6%
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP serv…
Mitigation only
CRITICAL 9.8
CVE-2025-65720
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted H…
Mitigation only
HIGH 7.8
CVE-2026-46709
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/path…
Tabby
1.0.234+
HIGH 8.8
CVE-2026-56197
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute …
Windows Admin Center
2606+
HIGH 7.1
CVE-2026-55145
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampe…
Copilot
Mitigation only
HIGH 7.8
CVE-2026-50488
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker t…
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
HIGH 7.8
CVE-2026-58635
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elev…
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 8.4
CVE-2026-50520
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute …
Visual Studio Code
1.128.1+
CRITICAL 9.6
CVE-2026-48561
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
365 Copilot
Mitigation only
MEDIUM 5.3
CVE-2026-15669
A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go …
Mitigation only
CRITICAL 9.3
CVE-2026-22095
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
Mitigation only
CRITICAL 9.3
CVE-2026-22103
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
Mitigation only