Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-8500
Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.
Web::Passwd is a small CGI application for managing htpasswd files using the htpass…
Mitigation only
CRITICAL 9.1
CVE-2026-44194EPSS 6%
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens…
Opnsense
26.1.8+
HIGH 7.2
CVE-2026-0261
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions…
Pan Os
10.2.7 / 10.2.10+
HIGH 8.8
CVE-2026-6281
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local networ…
Mitigation only
HIGH 8.7
CVE-2026-42924
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.8
CVE-2026-42290
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input…
Protobufjs Cli
1.2.1 / 2.0.2+
HIGH 8.7
CVE-2026-34176
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful…
Big Ip Access Policy Manager
after 17.5.1
CRITICAL 9.8
CVE-2026-42062
ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arb…
Mitigation only
HIGH 7.2
CVE-2026-35506
ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a craft…
Mitigation only
HIGH 7.2
CVE-2026-43685
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system com…
Filemaker Cloud
2.22.0.5+
CRITICAL 9.3
CVE-2026-44258
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and hom…
Mitigation only
HIGH 7.2
CVE-2026-23820
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execu…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.2
CVE-2026-23821
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system …
Arubaos
8.10.0.0 / 8.12.0.7+
HIGH 8.8
CVE-2026-41613
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.119.1+
MEDIUM 6.7
CVE-2025-53870
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, …
Fortiap
7.2.6 / 7.4.5+
MEDIUM 6.7
CVE-2025-53680
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiA…
Fortiap
7.0.6 / 7.4.5+
HIGH 8.4
CVE-2026-43991
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check…
Patch available
HIGH 8.4
CVE-2026-43990
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command …
Patch available
CRITICAL 9.8
CVE-2026-31226
The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) i…
Mitigation only
HIGH 7.2
CVE-2026-8051
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve …
Virtual Traffic Manager
after 22.8
HIGH 8.2
CVE-2026-35071
Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command I…
Insightiq
6.3.0+
HIGH 7.5
CVE-2025-40947
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX …
Ruggedcom Rox Mx5000 Firmware
2.17.1+
CRITICAL 9.1
CVE-2025-40949
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX …
Ruggedcom Rox Mx5000 Firmware
2.17.1+
HIGH 8.8
CVE-2026-7256
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow…
Wre6505 Firmware
Mitigation only
HIGH 7.8
CVE-2026-45391
A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary command…
Mitigation only
HIGH 7.8
CVE-2026-45393
A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr…
Mitigation only
HIGH 8.1
CVE-2026-30635
Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in t…
Mitigation only
HIGH 8.8
CVE-2026-7816
OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export.
User-supplied input was interpolated directly into a psql \copy…
Pgadmin 4
9.15+
MEDIUM 6.5
CVE-2026-31246
GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the Executor.run()…
Mitigation only
HIGH 8.0
CVE-2026-4802
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized…
Mitigation only