Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2025-37171
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su…
Arubaos
8.10.0.21 / 8.13.1.1+
HIGH 7.2
CVE-2025-37172
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su…
Arubaos
8.10.0.21 / 8.13.1.1+
HIGH 7.2
CVE-2025-37170
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Su…
Arubaos
8.10.0.21 / 8.13.1.1+
HIGH 8.6
CVE-2026-21267
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec…
Dreamweaver
21.7+
CRITICAL 9.8
CVE-2025-64155EPSS 43%
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.…
Fortisiem
7.1.9 / 7.2.7+
MEDIUM 6.8
CVE-2025-13447EPSS 26%
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe…
Connection Manager For Objectscale*
7.1.35.15 / 7.2.54.16+
MEDIUM 6.8
CVE-2025-13444EPSS 26%
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe…
Connection Manager For Objectscale
7.1.35.15 / 7.2.54.16+
HIGH 8.4
CVE-2026-0507
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrati…
Mitigation only
CRITICAL 9.8
CVE-2026-22781
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via …
Tinyweb
1.98+
HIGH 8.8
CVE-2026-0855
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitra…
Mitigation only
HIGH 8.8
CVE-2026-0854
Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary…
Mitigation only
CRITICAL 9.8
CVE-2025-69269
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, L…
Dx Netops Spectrum
23.3.7+
CRITICAL 9.8
CVE-2025-15502EPSS 6%
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro…
Operation And Maintenance Security Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15501EPSS 6%
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th…
Operation And Maintenance Security Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15500EPSS 6%
A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file …
Operation And Maintenance Management System
after 3.0.8
CRITICAL 9.8
CVE-2025-15499EPSS 5%
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o…
Operation And Maintenance Management System
after 3.0.8
HIGH 7.8
CVE-2026-0830
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE b…
Kiro Ide
0.6.18+
HIGH 7.2
CVE-2025-46645
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version …
Data Domain Operating System
7.10.1.80 / 7.13.1.50+
MEDIUM 6.7
CVE-2025-46644
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version …
Data Domain Operating System
7.10.1.80 / 7.13.1.50+
HIGH 7.2
CVE-2025-66052
Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" …
Ip7137 Firmware
Mitigation only
HIGH 8.8
CVE-2025-64091
This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
Tcis 3 Firmware
9.2.3.3+
HIGH 7.3
CVE-2026-22035
Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename …
Greenshot
1.3.311+
HIGH 8.8
CVE-2019-25289
SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter wi…
No fix yet
HIGH 8.8
CVE-2017-20215EPSS 14%
FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute s…
No fix yet
CRITICAL 9.8
CVE-2017-20216EPSS 11%
FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerF…
Mitigation only
HIGH 7.8
CVE-2025-69262
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np…
Pnpm
10.27.0+
MEDIUM 6.9
CVE-2025-6225
Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via logi…
Mitigation only
HIGH 7.2
CVE-2025-15472EPSS 20%
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of the component httpd . This ma…
Tew 811dru Firmware
No fix yet
CRITICAL 9.8
CVE-2025-15471EPSS 12%
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation…
Tew 713re Firmware
Mitigation only
HIGH 8.8
CVE-2020-36910
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers …
No fix yet