Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-25546
Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerabil…
Godot Mcp
0.1.1+
HIGH 8.8
CVE-2026-25512EPSS 19%
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote …
Group Office
6.8.150 / 25.0.82+
HIGH 7.8
CVE-2026-25143
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to…
Melange
0.40.5+
HIGH 7.5
CVE-2026-25157
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeC…
Openclaw
2026.1.29+
HIGH 8.8
CVE-2026-24844
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input …
Melange
after 0.40.5
HIGH 7.2
CVE-2026-21893
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s…
N8n
1.120.3+
CRITICAL 9.9
CVE-2026-25053
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users…
N8n
1.123.0 / 2.5.0+
HIGH 8.8
CVE-2026-24887
Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirm…
Claude Code
2.0.72+
CRITICAL 9.8
CVE-2025-52626
A Potential Command Injection vulnerability in HCL AION.
An This can allow unintended command execution, potentially leading to unauthorized actio…
Aion
Mitigation only
HIGH 8.8
CVE-2026-22550
OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS comman…
Wrc X1500gsa B Firmware
after 1.13
HIGH 7.8
CVE-2026-0383
A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely store…
Fabric Operating System
9.2.1c2 / 9.2.2b+
HIGH 8.8
CVE-2026-24763
OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed i…
Openclaw
2026.1.29+
HIGH 8.8
CVE-2026-23515
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated …
Signal K Server
1.5.0+
HIGH 8.0
CVE-2026-22223
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent
authenticated
attacker
execute arbitrary code. …
Archer Be230 Firmware
1.2.4+
HIGH 7.2
CVE-2026-22224
A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 …
Archer Be230 Firmware
1.2.4+
HIGH 7.2
CVE-2026-22225
A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2
and Arche…
Archer Be230 Firmware
1.2.4+
HIGH 7.2
CVE-2026-22226
A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1…
Archer Be230 Firmware
1.2.4+
HIGH 7.2
CVE-2026-22227
A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link …
Archer Be230 Firmware
1.2.4+
HIGH 7.2
CVE-2026-22229
A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the …
Archer Be230 Firmware
1.2.4+
HIGH 8.0
CVE-2026-22221
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent
authenticated
attacker
execute arbitrary code. …
Archer Be230 Firmware
1.2.4+
HIGH 8.0
CVE-2026-22222
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent
authenticated
attacker to execute arbitrary code.…
Archer Be230 Firmware
1.2.4+
HIGH 8.0
CVE-2026-0630
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent
authenticated
attacker to e…
Archer Be230 Firmware
1.2.4+
HIGH 8.0
CVE-2026-0631
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent
authenticated
attacker…
Archer Be230 Firmware
1.2.4+
HIGH 8.0
CVE-2025-9974
The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-l…
Mitigation only
HIGH 8.8
CVE-2026-24788
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by …
Mitigation only
HIGH 8.8
CVE-2020-37032
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system c…
Wing Ftp Server
No fix yet
CRITICAL 9.8
CVE-2020-37027
Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext…
Mitigation only
CRITICAL 9.6
CVE-2026-25130
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple…
Patch available
CRITICAL 9.2
CVE-2026-1723
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…
Mitigation only
CRITICAL 9.8
CVE-2025-51958
aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcomm…
Runcommand
Mitigation only