Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-40520
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation …
Api
17.0.8+
HIGH 8.8
CVE-2026-41036
This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authen…
Qn I 470 Firmware
Patch available
CRITICAL 9.8
CVE-2026-5965
NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands an…
Mitigation only
CRITICAL 9.8
CVE-2026-32311
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a u…
Flowsint
Patch available
HIGH 7.2
CVE-2026-24506
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.70+
HIGH 7.2
CVE-2026-26942
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command …
Powerprotect Dp Series Appliance
2.7.9 / 8.6.1.0+
HIGH 7.2
CVE-2026-26943
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.70+
HIGH 7.2
CVE-2026-22761
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access coul…
Powerprotect Dp Series Appliance
2.7.9 / 8.6.1.0+
HIGH 7.2
CVE-2026-23774
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.50+
HIGH 8.8
CVE-2026-5967
ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can injec…
Threatsonar Anti Ransomware
4.0.0+
CRITICAL 9.1
CVE-2026-6644
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…
Data Master
4.3.3.RR42 / 5.1.2.reo1+
HIGH 8.8
CVE-2026-35582
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection beca…
Emissary
8.43.0+
HIGH 7.8
CVE-2026-40527
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malici…
Radare2
6.1.6+
MEDIUM 6.3
CVE-2026-33145
xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsa…
Xrdp
0.10.6+
CRITICAL 9.1
CVE-2026-23500
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT …
Dolibarr Erp\/crm
23.0.0+
HIGH 7.2
CVE-2026-6483EPSS 14%
A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. …
Mitigation only
MEDIUM 6.7
CVE-2026-35072
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.70+
MEDIUM 6.7
CVE-2026-35073
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…
Data Domain Operating System
7.13.1.70 / 8.3.1.30+
MEDIUM 6.7
CVE-2026-35074
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.70+
HIGH 7.2
CVE-2026-21719
An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitr…
Cubecart
6.6.0+
HIGH 8.1
CVE-2026-41113
sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.
Patch available
CRITICAL 9.8
CVE-2026-6349
The
iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS command…
Mitigation only
HIGH 7.4
CVE-2026-41015
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed…
Patch available
HIGH 7.8
CVE-2026-40176
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce…
Composer
after 2.9.5
HIGH 8.8
CVE-2026-40261
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce…
Composer
after 2.9.5
HIGH 7.8
CVE-2026-40499
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute…
Radare2
after 6.1.4
HIGH 7.8
CVE-2026-33414
Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine b…
Podman
5.8.2+
HIGH 8.8
CVE-2026-35196
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/i…
Chamilo Lms
after 1.11.38
HIGH 8.8
CVE-2026-24893
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contai…
Openitcockpit
5.5.2+
CRITICAL 9.8
CVE-2026-39808 KEVEPSS 91%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…
Fortisandbox
after 4.4.9