Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2025-35028EPSS 5%
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI…
Mitigation only
CRITICAL 9.3
CVE-2025-8890
Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks.
In order…
Mitigation only
HIGH 8.0
CVE-2025-65202EPSS 7%
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameter…
Tew 657brm Firmware
No fix yet
CRITICAL 10.0
CVE-2025-64126
An OS command injection vulnerability exists due to improper input
validation. The application accepts a parameter directly from user input
without…
Mitigation only
CRITICAL 10.0
CVE-2025-64127
An OS command injection vulnerability exists due to insufficient
sanitization of user-supplied input. The application accepts parameters
that are l…
Mitigation only
CRITICAL 10.0
CVE-2025-64128
An OS command injection vulnerability exists due to incomplete
validation of user-supplied input. Validation fails to enforce
sufficient formatting…
Mitigation only
CRITICAL 9.8
CVE-2025-62354
Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands…
Mitigation only
CRITICAL 9.8
CVE-2025-66261
Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30…
Mozart Next 100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-66253
Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, …
Mozart Next 100 Firmware
Mitigation only
CRITICAL 9.2
CVE-2025-59366EPSS 16%
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality…
Mitigation only
HIGH 7.5
CVE-2025-59370
A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially exe…
Mitigation only
HIGH 7.5
CVE-2025-12742
A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters.
Loo…
Mitigation only
CRITICAL 9.3
CVE-2018-25126
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and…
No fix yet
CRITICAL 9.8
CVE-2025-64755
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code rea…
Claude Code
2.0.31+
MEDIUM 6.2
CVE-2025-13087EPSS 7%
A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges.…
Mitigation only
HIGH 7.3
CVE-2025-12121
Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized s…
Lite Xl
after 2.1.8
CRITICAL 9.8
CVE-2025-60738
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to e…
Eve X1 Server Firmware
Mitigation only
HIGH 7.3
CVE-2025-63932EPSS 8%
D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided b…
Dir 868l Firmware
No fix yet
HIGH 8.8
CVE-2025-34334
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in t…
Fax Server
after 2.6.23
HIGH 8.8
CVE-2025-34335
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability i…
Fax Server
2.6.23+
HIGH 7.2
CVE-2025-37163
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated at…
Airwave
8.3.0.5+
HIGH 8.8
CVE-2025-37157
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond…
Arubaos Cx
10.10.1170 / 10.13.1101+
HIGH 8.8
CVE-2025-37158
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond…
Arubaos Cx
10.10.1170 / 10.13.1101+
HIGH 7.2
CVE-2025-58034 KEVEPSS 56%
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW…
Fortiweb
7.0.12 / 7.2.12+
HIGH 7.8
CVE-2025-63408
Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive…
Agent Dvr
after 6.6.7.0
HIGH 8.8
CVE-2025-8693
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could …
Dm4200 B0 Firmware
after 5.63
HIGH 8.8
CVE-2025-13306EPSS 8%
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /bo…
Dwr M920 Firmware
No fix yet
HIGH 7.5
CVE-2025-64756
Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command…
Glob
10.5.0 / 11.1.0+
CRITICAL 9.8
CVE-2025-55055
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Rumpus
Mitigation only
HIGH 7.2
CVE-2025-34322EPSS 9%
Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries…
Log Server
2026+