Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2025-58059
Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admi…
Patch available
CRITICAL 9.8
CVE-2025-55583EPSS 6%
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component…
Dir 868l Firmware
Mitigation only
CRITICAL 10.0
CVE-2025-34160
AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/Ser…
Mitigation only
CRITICAL 10.0
CVE-2024-13985EPSS 13%
A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system command…
Mitigation only
CRITICAL 9.8
CVE-2018-25115EPSS 9%
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…
Dir 110 Firmware
Mitigation only
HIGH 8.8
CVE-2025-34161
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform …
Coolify
4.0.0+
MEDIUM 6.5
CVE-2025-20294
Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker wi…
Mitigation only
MEDIUM 6.0
CVE-2025-20295
A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to read or creat…
Mitigation only
CRITICAL 9.1
CVE-2025-50989EPSS 8%
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). …
Opnsense
25.1.8+
HIGH 7.2
CVE-2025-9528EPSS 48%
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand.…
E1700 Firmware
No fix yet
MEDIUM 6.5
CVE-2025-50974
The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p…
Ipfire
No fix yet
CRITICAL 9.8
CVE-2025-9424EPSS 18%
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch…
Ws7204 A Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-9387EPSS 9%
A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block…
Dcme 720 Firmware
Mitigation only
HIGH 8.1
CVE-2025-57771
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle proces…
Patch available
CRITICAL 9.8
CVE-2025-3128
A remote unauthenticated attacker who has bypassed authentication could
execute arbitrary OS commands to disclose, tamper with, destroy or
delete i…
Mitigation only
HIGH 8.1
CVE-2025-9262EPSS 5%
A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component o…
Mcp Cli
No fix yet
HIGH 8.8
CVE-2025-9244EPSS 8%
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/…
Re6250 Firmware
No fix yet
HIGH 8.5
CVE-2025-6181
The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escala…
Mitigation only
HIGH 7.0
CVE-2025-6183
The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a …
Mitigation only
CRITICAL 9.8
CVE-2011-10026
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation …
Spree
0.50.1+
CRITICAL 9.3
CVE-2010-20059
FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a c…
No fix yet
HIGH 7.8
CVE-2025-9176
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Var…
Shc
after 4.0.3
HIGH 7.8
CVE-2025-9174
A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filen…
Shc
after 4.0.3
MEDIUM 6.5
CVE-2025-55589
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff …
A3002r Firmware
No fix yet
HIGH 7.5
CVE-2025-55284
Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then s…
Claude Code
1.0.4+
CRITICAL 9.8
CVE-2025-9026
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple …
Dir 860l Firmware
Mitigation only
MEDIUM 6.0
CVE-2025-20220
A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could al…
Mitigation only
HIGH 8.8
CVE-2025-8876 KEV
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
N Central
2025.3.1+
CRITICAL 9.8
CVE-2025-43984EPSS 19%
An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerabl…
Mitigation only
CRITICAL 9.4
CVE-2012-10059
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The e…
No fix yet