Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-43879
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the …
Mitigation only
CRITICAL 9.8
CVE-2025-48890
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mini…
Mitigation only
CRITICAL 9.8
CVE-2025-6559
Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary…
Mitigation only
CRITICAL 10.0
CVE-2025-34041EPSS 7%
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.…
Mitigation only
CRITICAL 10.0
CVE-2025-34037EPSS 91%
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over …
Mitigation only
HIGH 8.8
CVE-2025-34033
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the we…
Blue Angel Software Suite
No fix yet
CRITICAL 9.8
CVE-2025-34035EPSS 12%
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to proper…
Esr300 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-34036EPSS 26%
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" tha…
Td 2108ts Cl Firmware
Mitigation only
MEDIUM 6.6
CVE-2025-2172EPSS 10%
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities,…
Mitigation only
HIGH 8.4
CVE-2025-23049
Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.
Mitigation only
MEDIUM 6.3
CVE-2025-6485EPSS 7%
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of …
A3002r Firmware
No fix yet
HIGH 8.8
CVE-2025-34024
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp end…
Ew 7438rpn Mini Firmware
after 1.13
HIGH 8.8
CVE-2025-34029
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /gofo…
Ew 7438rpn Mini Firmware
after 1.13
CRITICAL 10.0
CVE-2025-34030EPSS 60%
An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to saniti…
Mitigation only
CRITICAL 9.8
CVE-2025-25038EPSS 5%
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly s…
Minidvblinux
after 5.4
CRITICAL 9.8
CVE-2025-44635
There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG2-1350W, NR1200W series route…
Mitigation only
MEDIUM 5.9
CVE-2025-6193
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob c…
Patch available
CRITICAL 9.8
CVE-2025-50201
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was identified in the /html/configu…
Wegia
3.4.2+
HIGH 8.8
CVE-2025-6104
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file …
Mitigation only
HIGH 8.8
CVE-2025-6102
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown function…
Mitigation only
HIGH 8.8
CVE-2025-6103
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unkno…
Mitigation only
HIGH 7.2
CVE-2025-39240
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with va…
Mitigation only
HIGH 8.4
CVE-2025-4230
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run…
Mitigation only
CRITICAL 9.8
CVE-2025-41663
For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by W…
Mitigation only
HIGH 7.2
CVE-2025-31104
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1,…
Fortiadc
7.1.5 / 7.2.8+
HIGH 7.2
CVE-2024-13089
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS c…
Mitigation only
MEDIUM 5.5
CVE-2025-5743
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability exists that could cause remote contr…
Mitigation only
HIGH 7.3
CVE-2025-5952
A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file NSSD…
Mitigation only
HIGH 8.8
CVE-2025-49141
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a …
Haxcms Nodejs
11.0.0 / 11.0.3+
HIGH 8.8
CVE-2025-22481
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow rem…
Qts
Mitigation only