Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-34797
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi.…
Firewall Community
after 3.3.25
HIGH 8.8
CVE-2026-34794
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. …
Firewall Community
after 3.3.25
HIGH 8.8
CVE-2026-34795
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. …
Firewall Community
after 3.3.25
HIGH 8.8
CVE-2026-34792
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cg…
Firewall Community
after 3.3.25
HIGH 8.8
CVE-2026-34793
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.…
Firewall Community
after 3.3.25
HIGH 8.8
CVE-2026-34791
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi…
Firewall Community
after 3.3.25
HIGH 7.8
CVE-2026-33641
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which subst…
Glances
4.5.3+
HIGH 8.8
CVE-2026-3692
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the repo…
Flowmon
12.5.8+
HIGH 8.8
CVE-2026-2701EPSS 57%
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
Sharefile Storage Zones Controller
5.12.4+
HIGH 8.8
CVE-2026-33613
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpAr…
Mbconnect24
after 2.19.4
HIGH 7.3
CVE-2026-1345
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…
Security Verify Access
after 11.0.2.0
MEDIUM 6.8
CVE-2026-24154
NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A …
Jetson Linux
35.6.4 / 36.5+
CRITICAL 9.8
CVE-2026-34243
wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Action…
Wenxian
after 0.3.1
CRITICAL 9.8
CVE-2026-30312
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…
Mitigation only
CRITICAL 9.8
CVE-2026-30314
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…
Auto Approval Module
after 0.1.1
HIGH 7.8
CVE-2026-30309
InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely…
Infcode
after 1.3.1
CRITICAL 9.8
CVE-2026-30311
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…
Auto Approval Module
after 0.1.1
HIGH 7.8
CVE-2026-0596
A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into…
Mlflow
No fix yet
CRITICAL 9.8
CVE-2026-32917
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute …
Openclaw
2026.3.13+
HIGH 8.3
CVE-2025-14213
Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket …
Mitigation only
CRITICAL 9.8
CVE-2026-30880
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue …
Basercms
5.2.3+
HIGH 7.2
CVE-2026-21861
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update funct…
Basercms
5.2.3+
HIGH 7.2
CVE-2026-30877
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due …
Basercms
5.2.3+
HIGH 8.6
CVE-2026-34714
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injectio…
Vim
9.2.0272+
MEDIUM 5.3
CVE-2026-5125
A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file …
Patch available
CRITICAL 9.9
CVE-2026-33030
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) …
Nginx Ui
after 2.3.3
CRITICAL 9.8
CVE-2025-15379
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to…
Mlflow
after 3.8.1
HIGH 8.8
CVE-2026-5101
A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the…
A3300r Firmware
No fix yet
HIGH 8.8
CVE-2026-4946
Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary comm…
Ghidra
12.0.3+
HIGH 8.8
CVE-2026-34005
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the Ho…
Mitigation only