Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-67041
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti…
Eds3016ps1ns Firmware
Mitigation only
HIGH 7.8
CVE-2024-14026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who h…
Qts
Mitigation only
HIGH 7.2
CVE-2026-23816
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the un…
Arubaos Cx
after 10.17.0001
CRITICAL 9.8
CVE-2026-28292
`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacke…
Simple Git
3.32.2+
HIGH 7.2
CVE-2026-25836
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, For…
Fortisandbox Cloud
Mitigation only
HIGH 7.2
CVE-2025-66178
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, …
Fortiweb
7.0.13 / 7.2.13+
CRITICAL 9.8
CVE-2025-41709
An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.
Mitigation only
HIGH 8.8
CVE-2026-26982
Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used …
Ghostty
1.3.0+
HIGH 7.2
CVE-2026-25041
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration construc…
Budibase
after 3.23.22
CRITICAL 9.8
CVE-2025-70039
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
Twake
Mitigation only
HIGH 8.0
CVE-2025-15568
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network…
Archer Axe75 Firmware
1.3.2+
CRITICAL 9.8
CVE-2026-3696
A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi…
N300rh Firmware
Mitigation only
HIGH 8.8
CVE-2026-30861
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an …
Weknora
0.2.10+
CRITICAL 9.8
CVE-2026-25070
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endp…
Zikestor Sks8310 8x Firmware
after 1.04.b07
HIGH 7.8
CVE-2026-29783
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter ex…
Copilot Command Line Interface
0.0.423+
CRITICAL 9.8
CVE-2026-29058
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj…
Avideo Encoder
7.0+
HIGH 7.2
CVE-2026-28507
Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and templa…
Known
1.6.4+
CRITICAL 9.8
CVE-2026-28470
OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit…
Openclaw
2026.2.2+
MEDIUM 5.5
CVE-2026-28463
OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansio…
Openclaw
2026.2.14+
CRITICAL 9.8
CVE-2026-28391
OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat…
Openclaw
2026.2.2+
HIGH 8.8
CVE-2026-28287EPSS 8%
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu…
Freepbx
16.0.20 / 17.0.5+
HIGH 7.2
CVE-2026-28209
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerabi…
Freepbx
16.0.20 / 17.0.5+
MEDIUM 6.0
CVE-2026-20008
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …
Adaptive Security Appliance Software
7.0.9 / 7.2.11+
CRITICAL 9.8
CVE-2026-26478
A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craf…
Tichome Mini Firmware
Mitigation only
HIGH 7.2
CVE-2025-59783
API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injecti…
Access Commander
3.4.2+
CRITICAL 9.8
CVE-2026-27441
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.
Seppmail
15.0.1+
HIGH 8.8
CVE-2026-28773
The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver We…
Sfx2100 Firmware
No fix yet
HIGH 8.8
CVE-2026-28774
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series…
Sfx2100 Firmware
No fix yet
CRITICAL 9.1
CVE-2026-26279
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disable…
Froxlor
2.3.4+
CRITICAL 9.8
CVE-2026-3485
A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument…
Dir 868l Firmware
Mitigation only