Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-58180EPSS 21%
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability tha…
Octoprint
1.11.3+
CRITICAL 9.8
CVE-2025-55048
Multiple CWE-78
No fix yet
MEDIUM 6.7
CVE-2024-45325
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F versio…
Fortiddos F
7.0.3+
CRITICAL 9.3
CVE-2025-54994
@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written i…
Patch available
HIGH 7.8
CVE-2025-58374
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands…
Roo Code
3.26.0+
HIGH 8.1
CVE-2025-58370
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing …
Roo Code
3.26.0+
CRITICAL 9.8
CVE-2025-58371
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull…
Roo Code
3.26.7+
CRITICAL 9.8
CVE-2025-55037
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If th…
Mitigation only
HIGH 8.4
CVE-2025-56803
Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS…
Desktop
No fix yet
MEDIUM 5.3
CVE-2025-56498
An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submi…
Pgn6401v Firmware
after 8.1.2
HIGH 7.2
CVE-2025-8613
Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…
Mitigation only
HIGH 8.6
CVE-2025-9573
The ns_backup extension through 13.0.2 for TYPO3 allows command injection.
Mitigation only
HIGH 8.7
CVE-2025-57799
StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker c…
Patch available
CRITICAL 9.8
CVE-2025-54857
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8 and earl…
Mitigation only
CRITICAL 9.8
CVE-2025-9752EPSS 16%
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component …
Dir 852 Firmware
Mitigation only
HIGH 7.2
CVE-2025-9745EPSS 10%
A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.a…
Di 500wf Firmware
No fix yet
CRITICAL 9.8
CVE-2025-9727
A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulatio…
Dir 816l Firmware
Mitigation only
CRITICAL 10.0
CVE-2009-20011
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure h…
Mitigation only
CRITICAL 9.3
CVE-2009-20010
Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability ar…
No fix yet
HIGH 8.8
CVE-2005-10004
Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbit…
Cacti
0.8.6d+
CRITICAL 9.8
CVE-2024-46484
TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.
Tv Ip410 Firmware
Mitigation only
HIGH 7.2
CVE-2025-9377 KEVEPSS 12%
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) …
Tl Wr841n Firmware
241108+
HIGH 8.4
CVE-2025-44015
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit th…
Hybriddesk Station
4.2.18+
HIGH 8.8
CVE-2025-30264
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they…
Qts
Mitigation only
HIGH 7.2
CVE-2025-29887
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then expl…
Qurouter
Mitigation only
HIGH 7.2
CVE-2025-53508
Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed and se…
Mitigation only
HIGH 7.3
CVE-2025-58062
LSTM-Kirigaya's openmcp-client is a vscode plugin for mcp developer. Prior to version 0.1.12, when users on a Windows platform connect to an attacker…
Patch available
HIGH 8.8
CVE-2025-9579EPSS 7%
A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the compo…
Bl X26 Firmware
No fix yet
HIGH 8.8
CVE-2025-9580EPSS 7%
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the compone…
Bl X26 Firmware
No fix yet
HIGH 8.8
CVE-2025-9575EPSS 8%
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. …
Re6250 Firmware
No fix yet