Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.3
CVE-2013-3307EPSS 53%
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacte…
Mitigation only
MEDIUM 6.7
CVE-2025-52988
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS a…
Junos
21.2 / 22.4+
CRITICAL 9.5
CVE-2025-50121EPSS 18%
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability exists that could cause unauthenti…
Mitigation only
HIGH 8.0
CVE-2025-53637
Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has ext…
Meshtastic Firmware
2.6.6+
HIGH 8.8
CVE-2025-7414EPSS 13%
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /go…
O3 Firmware
No fix yet
CRITICAL 9.3
CVE-2025-34102EPSS 7%
A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and c…
No fix yet
CRITICAL 9.3
CVE-2025-34099
An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php compone…
No fix yet
CRITICAL 9.3
CVE-2025-34101
An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoi…
No fix yet
HIGH 7.5
CVE-2025-34093
An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute …
No fix yet
CRITICAL 9.3
CVE-2025-34095
An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples…
No fix yet
HIGH 7.7
CVE-2025-53542
Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script used in the macOS packaging w…
Patch available
HIGH 8.6
CVE-2025-46334
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv f…
Mitigation only
HIGH 8.6
CVE-2025-27614
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a u…
Patch available
HIGH 8.8
CVE-2025-7407EPSS 9%
A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manip…
D6400 Firmware
No fix yet
CRITICAL 9.6
CVE-2025-6514EPSS 78%
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response …
Patch available
CRITICAL 10.0
CVE-2025-3499
The device has two web servers that expose unauthenticated REST APIs on the management network (TCP
ports 8084 and 8086). Exploiting OS command injec…
Mitigation only
HIGH 7.9
CVE-2025-49537
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co…
Coldfusion
Mitigation only
HIGH 7.2
CVE-2025-6771EPSS 17%
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker w…
Endpoint Manager Mobile
12.3.0.3 / 12.4.0.3+
HIGH 7.2
CVE-2025-6770EPSS 16%
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to …
Endpoint Manager Mobile
12.3.0.3 / 12.4.0.3+
HIGH 8.4
CVE-2025-25269
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
Charx Sec 3000 Firmware
1.7.3+
HIGH 8.8
CVE-2025-7154
A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this is…
N200re Firmware
No fix yet
MEDIUM 6.8
CVE-2025-20319
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability `edit_script…
Splunk
9.1.10 / 9.2.7+
HIGH 8.8
CVE-2025-53376
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated…
Dokploy
0.23.7+
MEDIUM 6.8
CVE-2025-3705
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS …
Mitigation only
CRITICAL 9.1
CVE-2025-3626
A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Com…
Mitigation only
CRITICAL 9.8
CVE-2025-48501
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be…
Mitigation only
HIGH 7.2
CVE-2025-7145
ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermedia…
Mitigation only
HIGH 8.8
CVE-2025-7097
A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown pr…
Internet Security
No fix yet
HIGH 8.8
CVE-2025-7083EPSS 41%
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the c…
F9k1122 Firmware
No fix yet
HIGH 8.8
CVE-2025-7081EPSS 17%
A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is the function formSetWanStatic …
F9k1122 Firmware
No fix yet