Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2025-43908
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…
Data Domain Operating System
7.10.1.70 / 7.13.1.40+
MEDIUM 6.7
CVE-2025-43890
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…
Data Domain Operating System
7.10.1.70 / 7.13.1.40+
MEDIUM 6.7
CVE-2025-43906
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…
Data Domain Operating System
7.10.1.70 / 7.13.1.40+
MEDIUM 6.7
CVE-2025-43911
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…
Data Domain Operating System
7.10.1.70 / 7.13.1.40+
HIGH 8.8
CVE-2025-54403
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request…
Wgr 500 Firmware
No fix yet
HIGH 8.8
CVE-2025-54404
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request…
Wgr 500 Firmware
No fix yet
HIGH 8.8
CVE-2025-54405
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of …
Wgr 500 Firmware
No fix yet
HIGH 8.8
CVE-2025-54406
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of …
Wgr 500 Firmware
No fix yet
HIGH 8.2
CVE-2025-60962
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain se…
Sonoma D12 Firmware
Mitigation only
HIGH 8.2
CVE-2025-60963
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…
Sonoma D12 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-60964
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…
Sonoma D12 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-60965
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…
Sonoma D12 Firmware
Mitigation only
CRITICAL 9.9
CVE-2025-60957
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…
Sonoma D12 Firmware
Mitigation only
HIGH 8.2
CVE-2025-60959
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain se…
Sonoma D12 Firmware
Mitigation only
HIGH 8.2
CVE-2025-60960
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute…
Sonoma D12 Firmware
Mitigation only
HIGH 7.3
CVE-2025-36354
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0
could allow an unauthent…
Security Verify Access
10.0.9.0 / 11.0.1.0+
HIGH 8.8
CVE-2025-11285EPSS 8%
A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverC…
Mcphub
after 0.9.10
HIGH 7.2
CVE-2025-47212
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…
Qts
Mitigation only
HIGH 8.8
CVE-2025-61591
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an…
Cursor
after 1.7
HIGH 7.2
CVE-2025-60787EPSS 18%
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is w…
Motioneye
No fix yet
CRITICAL 9.8
CVE-2025-59741
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-59735
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-59736
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-59737
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-59738
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-59739
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-59740
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system command…
E Tms
Mitigation only
CRITICAL 9.8
CVE-2025-61045
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg fun…
X18 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-10659
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supp…
Mitigation only
CRITICAL 9.8
CVE-2025-9762
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function i…
Mitigation only