Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-6541
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Er706w Firmware
1.0.3 / 1.1.4+
CRITICAL 10.0
CVE-2018-25118
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that ena…
Mitigation only
HIGH 8.8
CVE-2025-47900
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…
Timeprovider 4100 Firmware
2.5+
HIGH 8.8
CVE-2025-47901
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…
Timeprovider 4100 Firmware
2.5+
CRITICAL 9.8
CVE-2025-11900
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands…
Mitigation only
CRITICAL 9.8
CVE-2025-34513EPSS 8%
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauth…
Eve X1 Server Firmware
after 4.7.18.0
HIGH 8.8
CVE-2025-34514
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scri…
Eve X1 Server Firmware
after 4.7.18.0
HIGH 8.7
CVE-2025-53868
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restricti…
Big Ip Access Policy Manager
15.1.10.8 / 16.1.6.1+
CRITICAL 9.3
CVE-2023-7311
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is n…
No fix yet
CRITICAL 9.3
CVE-2023-7304
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker…
Mitigation only
HIGH 8.6
CVE-2025-59051
The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device disco…
Mitigation only
HIGH 7.0
CVE-2024-48891
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1…
Fortisoar
7.5.2 / 7.6.2+
HIGH 7.2
CVE-2025-5946EPSS 14%
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload …
Centreon Web
23.10.28 / 24.04.18+
HIGH 7.2
CVE-2025-10242EPSS 21%
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+
HIGH 7.2
CVE-2025-10243EPSS 21%
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+
HIGH 7.2
CVE-2025-10985EPSS 21%
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+
HIGH 7.2
CVE-2025-47856
Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice versio…
Fortivoice
6.4.11 / 7.0.7+
CRITICAL 9.0
CVE-2025-9976
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPE…
Mitigation only
CRITICAL 9.8
CVE-2025-11665EPSS 7%
A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Updat…
Dap 2695 Firmware
Mitigation only
HIGH 8.4
CVE-2025-0636
EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Ar…
Mitigation only
HIGH 8.7
CVE-2016-15047
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in C…
No fix yet
MEDIUM 5.3
CVE-2025-60006
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability in the CLI of Jun…
Junos Os Evolved
Mitigation only
HIGH 7.2
CVE-2025-10239
In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the managemen…
Mitigation only
CRITICAL 9.8
CVE-2025-11491
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/comma…
Desktopcommandermcp
after 0.2.13
HIGH 8.8
CVE-2025-57457
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the…
Mitigation only
CRITICAL 9.8
CVE-2025-11490
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file …
Desktopcommandermcp
after 0.2.13
MEDIUM 6.7
CVE-2025-36567
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…
Data Domain Operating System
7.10.1.60 / 7.13.1.30+
MEDIUM 6.7
CVE-2025-36569
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…
Data Domain Operating System
7.10.1.60 / 7.13.1.30+
CRITICAL 9.8
CVE-2025-11407
A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation …
Di 7001mini 8g Firmware
Mitigation only
MEDIUM 6.7
CVE-2025-36566
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Version…
Data Domain Operating System
7.10.1.60 / 7.13.1.30+