Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-27849
Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normall…
Mitigation only
MEDIUM 6.7
CVE-2026-20099
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local …
Mitigation only
MEDIUM 6.5
CVE-2026-20036
A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with valid …
Mitigation only
CRITICAL 9.8
CVE-2026-27848
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as…
Mitigation only
CRITICAL 9.9
CVE-2026-27626
OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec…
Olivetin
after 3000.10.0
CRITICAL 9.8
CVE-2026-22553
All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that…
Masterscada
Mitigation only
HIGH 8.8
CVE-2026-23678
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnosti…
10g08 0800gsm Firmware
Mitigation only
HIGH 8.8
CVE-2026-3101EPSS 6%
A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation res…
Tip 635g Firmware
No fix yet
HIGH 8.8
CVE-2026-3102
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm…
Exiftool
13.50+
HIGH 7.8
CVE-2026-27208
bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and P…
Api Gateway Deploy
Mitigation only
HIGH 8.8
CVE-2026-26331
yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-…
Yt Dlp
2026.02.21+
CRITICAL 9.8
CVE-2025-13942
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attack…
Wx5610 B0 Firmware
1.00 / 1.16+
HIGH 8.8
CVE-2025-13943
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)…
Ex5601 T1 Firmware
5.17 / 5.18+
HIGH 7.2
CVE-2026-1459
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions thro…
Vmg3625 T50c Firmware
after 5.50
HIGH 7.2
CVE-2026-3040EPSS 9%
A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload…
Vigor300b Firmware
after 1.5.1.6
HIGH 8.8
CVE-2025-70328
TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executa…
X6000r Firmware
No fix yet
HIGH 8.0
CVE-2025-70329
TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable…
X5000r Firmware
No fix yet
CRITICAL 9.8
CVE-2026-2952EPSS 7%
A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request …
Vaelsys
Mitigation only
CRITICAL 9.8
CVE-2026-2944EPSS 6%
A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file …
Online Store Management System
Mitigation only
HIGH 8.0
CVE-2026-27487
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a…
Openclaw
2026.2.14+
HIGH 7.2
CVE-2026-26046
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command in…
Moodle
4.5.9 / 5.0.5+
HIGH 8.8
CVE-2026-2041EPSS 73%
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…
Nagios Xi
Mitigation only
HIGH 8.8
CVE-2026-2042EPSS 6%
Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…
Nagios Xi
Mitigation only
HIGH 8.8
CVE-2026-2043EPSS 73%
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…
Nagios Xi
Mitigation only
MEDIUM 6.8
CVE-2026-2035
Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …
Patch available
CRITICAL 9.8
CVE-2019-25441EPSS 8%
thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting mal…
Thesystem
Mitigation only
MEDIUM 6.3
CVE-2026-27113
Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3ea…
Patch available
CRITICAL 9.8
CVE-2026-27190
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process impl…
Deno
2.6.8+
CRITICAL 10.0
CVE-2021-35402
PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter…
Mitigation only
HIGH 7.2
CVE-2026-2846EPSS 10%
A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of…
520 Firmware
No fix yet