Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-14522
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
HIGH 8.3
CVE-2026-22621
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administ…
No fix yet
HIGH 8.8
CVE-2026-22622
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to …
No fix yet
HIGH 7.8
CVE-2026-44106
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as roo…
No fix yet
HIGH 7.8
CVE-2026-44099
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting …
No fix yet
HIGH 7.8
CVE-2026-44093
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands …
No fix yet
HIGH 7.8
CVE-2026-44095
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as r…
No fix yet
HIGH 7.8
CVE-2026-44096
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compro…
No fix yet
HIGH 8.6
CVE-2026-44098
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injectio…
No fix yet
HIGH 7.8
CVE-2026-16524
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed valid…
No fix yet
MEDIUM 6.6
CVE-2026-67438
OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go ch…
No fix yet
MEDIUM 6.8
CVE-2026-56389
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration var…
No fix yet
HIGH 7.2
CVE-2026-14958
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Aspera Faspex
5.0.16+
HIGH 7.2
CVE-2026-14959
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Aspera Faspex
5.0.16+
HIGH 7.2
CVE-2026-59764
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an …
No fix yet
HIGH 7.2
CVE-2026-61376
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exp…
No fix yet
HIGH 8.8
CVE-2026-54540
Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass…
No fix yet
HIGH 8.8
CVE-2026-55578
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses a…
No fix yet
CRITICAL 9.9
CVE-2026-48030EPSS 5%
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability i…
No fix yet
HIGH 7.8
CVE-2026-24252
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead …
No fix yet
CRITICAL 10.0
CVE-2026-16812 KEV
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…
Velocloud Orchestrator
5.2.3.14 / 6.1.3.4+
HIGH 8.5
CVE-2025-59172
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacke…
No fix yet
HIGH 8.4
CVE-2026-59687
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…
Connection Manager For Objectscale
7.2.54.19 / 7.2.63.3+
HIGH 8.4
CVE-2026-59688
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…
Connection Manager For Objectscale
7.2.54.19 / 7.2.63.3+
HIGH 8.4
CVE-2026-59686
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…
Connection Manager For Objectscale
7.2.54.19 / 7.2.63.3+
HIGH 8.3
CVE-2026-17497
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the defa…
No fix yet
CRITICAL 9.8
CVE-2026-16766
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.
Options are passed directly t…
No fix yet
HIGH 7.2
CVE-2026-65711
sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands …
No fix yet
HIGH 7.2
CVE-2026-66138
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic…
No fix yet
CRITICAL 9.9
CVE-2026-63732
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation…
No fix yet