Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2025-63916
MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize…
Myscreentools
after 2.2.1.0
CRITICAL 9.8
CVE-2025-13284
ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands a…
Mitigation only
CRITICAL 9.3
CVE-2021-4470
TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed dir…
Mitigation only
HIGH 8.7
CVE-2021-4466
IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. …
No fix yet
HIGH 7.2
CVE-2025-64444
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploi…
Mitigation only
HIGH 8.8
CVE-2025-20349
A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted …
Catalyst Center
2.3.7.10+
HIGH 8.8
CVE-2025-12763
pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True duri…
Pgadmin 4
9.10+
MEDIUM 6.8
CVE-2025-42892
Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc…
Business Connector
Mitigation only
CRITICAL 10.0
CVE-2025-10230EPSS 40%
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validati…
Mitigation only
HIGH 7.2
CVE-2025-64328 KEVEPSS 85%
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor…
Filestore
17.0.3+
CRITICAL 9.3
CVE-2025-11546
CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe …
Mitigation only
HIGH 7.8
CVE-2025-12489
evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege…
Patch available
HIGH 7.2
CVE-2025-34239
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows a…
Webaccess\/vpn
1.1.5+
CRITICAL 9.8
CVE-2022-50596
D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management inter…
Dir 1260 Firmware
after 1.20b05
CRITICAL 9.8
CVE-2025-63334
PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The…
Pocketvj Control Panel Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-45378
Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command s…
Cloudlink
after 8.1.2
HIGH 8.4
CVE-2025-45379
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to …
Cloudlink
8.2+
HIGH 7.2
CVE-2025-30479
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control …
Cloudlink
8.2+
CRITICAL 9.8
CVE-2025-61304
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
Activegate Ping Extension
after 1.016
HIGH 8.0
CVE-2025-10622
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve …
Mitigation only
HIGH 8.8
CVE-2025-64109
Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to achieve r…
Mitigation only
HIGH 8.8
CVE-2025-64106
Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation ena…
Cursor
2.0+
CRITICAL 9.8
CVE-2025-11953 KEVEPSS 94%
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpo…
React Native Community Cli
19.1.2+
HIGH 7.2
CVE-2025-54763
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of…
Mitigation only
HIGH 7.2
CVE-2025-34280
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate…
Network Analyzer
2024+
HIGH 8.8
CVE-2025-34284
Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters…
Nagios Xi
2024+
HIGH 7.2
CVE-2025-34286
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient va…
Nagios Xi
2026+
HIGH 8.8
CVE-2024-14005
Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input i…
Nagios Xi
2024+
HIGH 7.2
CVE-2024-14008
Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of…
Nagios Xi
2024+
HIGH 7.2
CVE-2025-34134
Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficie…
Nagios Xi
2024+