Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-42922
AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
Aapanel
after 7.0.7
MEDIUM 6.5
CVE-2025-27804
Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted messag…
Mitigation only
CRITICAL 9.8
CVE-2025-44880
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a c…
Wl Wn579a3 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-44882
A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands vi…
Wl Wn579a3 Firmware
No fix yet
HIGH 8.8
CVE-2025-41225
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run sc…
Mitigation only
HIGH 7.2
CVE-2024-6486
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" param…
Imagemagick Engine
1.7.11+
CRITICAL 9.8
CVE-2025-32002
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T…
Mitigation only
HIGH 8.9
CVE-2025-47782
motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, …
Patch available
HIGH 8.5
CVE-2025-24022
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend o…
Itop
2.7.12 / 3.1.3+
CRITICAL 9.1
CVE-2025-43562EPSS 45%
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2025-45858EPSS 11%
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.
A3002r Firmware
No fix yet
HIGH 7.8
CVE-2025-40582
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affecte…
Scalance Lpe9403 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-26389
A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanit…
Ozw672 Firmware
8.0+
HIGH 7.2
CVE-2025-32821EPSS 20%
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command argu…
Sma 100 Firmware
10.2.1.15-81sv+
MEDIUM 5.5
CVE-2025-20213
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite…
Catalyst Sd Wan Manager
Mitigation only
MEDIUM 6.5
CVE-2025-20193
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perfo…
Ios Xe
Mitigation only
MEDIUM 5.4
CVE-2025-20194
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perfo…
Ios Xe
Mitigation only
HIGH 8.8
CVE-2025-20186
A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, r…
Ios Xe
Mitigation only
CRITICAL 9.8
CVE-2025-45491
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parame…
E5600 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45042
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
Ac9 Firmware
No fix yet
HIGH 8.8
CVE-2025-2605EPSS 13%
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abus…
Mb Secure Firmware
03.09 / 12.53+
HIGH 7.8
CVE-2024-6032
Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code…
Model S Firmware
2024.8+
HIGH 8.8
CVE-2025-24351
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to e…
Mitigation only
HIGH 8.1
CVE-2025-4032
A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the…
Aworld
after 2025-04-24
HIGH 8.8
CVE-2022-41871
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context…
Seppmail
after 12.1.17
CRITICAL 9.1
CVE-2025-46271
UNI-NMS-Lite is vulnerable to a command injection attack that could
allow an unauthenticated attacker to read or manipulate device data.
Mitigation only
CRITICAL 9.1
CVE-2025-46272
WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection
attack that could allow an unauthenticated attacker to execute OS
commands on …
Mitigation only
CRITICAL 9.2
CVE-2025-43858
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, a…
Patch available
MEDIUM 6.7
CVE-2025-1976 KEV
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary…
Fabric Operating System
9.1.1d7+
HIGH 7.2
CVE-2025-2773
BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…
Router Firmware
Mitigation only