Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-0273
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run…
Pan Os
10.2.7 / 10.2.10+
HIGH 7.5
CVE-2026-6893
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Hos…
Mitigation only
HIGH 7.5
CVE-2026-46643
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/…
Mitigation only
HIGH 8.5
CVE-2026-9151
An OS
command injection vulnerability exists in the VPN module of TP-Link Archer AX12
v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerabili…
Mitigation only
MEDIUM 6.9
CVE-2026-46618
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…
Patch available
HIGH 7.3
CVE-2026-11417
OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who contro…
Mitigation only
HIGH 8.8
CVE-2026-45564
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>…
Mitigation only
CRITICAL 9.9
CVE-2026-45556
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>…
Mitigation only
CRITICAL 9.9
CVE-2026-45558
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi…
Mitigation only
HIGH 7.2
CVE-2026-24719
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…
Qts
5.2.9.3492+
HIGH 7.2
CVE-2026-22893
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…
Qts
5.2.9.3410+
HIGH 7.2
CVE-2025-66273
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…
Qts
5.2.9.3410+
HIGH 7.2
CVE-2025-66279
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…
Qts
5.2.9.3410+
HIGH 8.8
CVE-2026-49959
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands…
Patch available
CRITICAL 9.8
CVE-2026-38615
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Mitigation only
CRITICAL 9.8
CVE-2026-25089 KEVEPSS 74%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…
Fortisandbox
4.4.9 / 5.0.6+
CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…
Standalone Sentry
10.5.2 / 10.6.2+
HIGH 7.2
CVE-2026-10727EPSS 14%
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execut…
Mitigation only
HIGH 8.7
CVE-2026-9279
Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, …
Mitigation only
HIGH 8.8
CVE-2026-46746
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /ap…
Sinec Ins
after 1.0
HIGH 8.8
CVE-2026-11572
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user inpu…
Patch available
HIGH 7.5
CVE-2026-40519
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS comm…
Patch available
MEDIUM 6.5
CVE-2026-10544
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated us…
Devolutions Server
2026.1.21.0+
HIGH 8.5
CVE-2026-8913
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled i…
Mitigation only
HIGH 8.8
CVE-2026-11556
A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the co…
Mitigation only
HIGH 8.8
CVE-2026-25855
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by upl…
Mitigation only
MEDIUM 6.3
CVE-2026-11408
A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of t…
Patch available
CRITICAL 9.8
CVE-2026-45777
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remot…
Open Xdmod
11.0.3+
MEDIUM 6.0
CVE-2026-25620EPSS 10%
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Ne…
Ng Firewall
Mitigation only
MEDIUM 6.0
CVE-2026-25621
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure i…
Ng Firewall
Mitigation only