Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.0
CVE-2026-25622EPSS 10%
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On …
Ng Firewall
17.4.1+
MEDIUM 6.0
CVE-2026-25623EPSS 6%
An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generati…
Ng Firewall
17.4.1+
HIGH 7.7
CVE-2026-46394
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git…
Mitigation only
CRITICAL 9.4
CVE-2026-46399
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file ove…
Mitigation only
HIGH 8.8
CVE-2026-49492
Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken …
Mitigation only
CRITICAL 9.0
CVE-2026-45750
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…
Termix
2.3.2+
CRITICAL 9.8
CVE-2026-45748
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint…
Termix
2.3.2+
CRITICAL 9.9
CVE-2026-45744
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…
Termix
2.3.2+
MEDIUM 6.3
CVE-2026-11341
A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipu…
Mitigation only
HIGH 8.8
CVE-2026-21837
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary o…
Digital Experience
Mitigation only
HIGH 7.2
CVE-2026-10872
A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. P…
Mitigation only
HIGH 7.2
CVE-2026-10873
A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Exec…
Mitigation only
HIGH 7.2
CVE-2026-10871
A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the compo…
Mitigation only
HIGH 7.2
CVE-2026-10870
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulati…
Mitigation only
HIGH 8.2
CVE-2025-69755
An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a …
Mitigation only
HIGH 7.5
CVE-2026-10796
nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands …
Node Version Manager
0.40.5+
CRITICAL 9.8
CVE-2025-67447
The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does n…
Mitigation only
CRITICAL 9.6
CVE-2026-35906
An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary …
Mitigation only
HIGH 8.7
CVE-2026-45431
This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web manageme…
Mitigation only
HIGH 7.2
CVE-2026-3820
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.
An attacker may obtain administrator privileges and inject…
Mitigation only
MEDIUM 6.8
CVE-2026-50206
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
Connect M6e 5g Firmware
Mitigation only
HIGH 8.8
CVE-2026-49190
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installa…
Connect M6e 5g Firmware
Mitigation only
MEDIUM 6.7
CVE-2026-10805
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malform…
Mitigation only
CRITICAL 9.8
CVE-2026-49185
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
Connect M6e 5g Firmware
Mitigation only
HIGH 8.2
CVE-2026-41010
ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name retu…
Mitigation only
HIGH 8.2
CVE-2026-41011
PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['nam…
No fix yet
CRITICAL 9.8
CVE-2026-36576
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arb…
Mitigation only
HIGH 8.0
CVE-2026-47294
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attack…
Sharepoint Server
16.0.19725.20280+
MEDIUM 6.3
CVE-2026-10279
A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts …
Mitigation only
HIGH 7.3
CVE-2026-10273
A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webho…
Patch available