Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-28035
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through th…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2025-28036
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through t…
A950rg Firmware
No fix yet
CRITICAL 9.8
CVE-2025-28038
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through…
Ex1200t Firmware
No fix yet
CRITICAL 9.8
CVE-2025-28039
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through …
Ex1200t Firmware
No fix yet
CRITICAL 9.8
CVE-2025-28037
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in …
A810r Firmware
No fix yet
CRITICAL 9.8
CVE-2025-28034
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5…
A800r Firmware
No fix yet
HIGH 8.1
CVE-2025-43920
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrar…
Mailman
after 2.1.39
HIGH 7.2
CVE-2025-3816EPSS 6%
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save…
Cicadascms
No fix yet
CRITICAL 9.8
CVE-2025-29042
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c
Dir 823x Firmware
No fix yet
CRITICAL 9.8
CVE-2025-29043
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
Dir 823x Firmware
No fix yet
CRITICAL 9.8
CVE-2025-29040
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
Dir 823x Firmware
No fix yet
CRITICAL 9.8
CVE-2025-29041
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c
Dir 823x Firmware
No fix yet
CRITICAL 9.8
CVE-2025-3729
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe…
Web Based Pharmacy Product Management System
No fix yet
CRITICAL 9.3
CVE-2025-32778EPSS 19%
Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check proj…
Patch available
CRITICAL 9.8
CVE-2025-28137EPSS 14%
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function throu…
A810r Firmware
No fix yet
MEDIUM 6.3
CVE-2025-0119
A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with …
Mitigation only
HIGH 8.0
CVE-2025-32107
OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerabil…
Mitigation only
HIGH 7.1
CVE-2025-0127
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run…
Mitigation only
HIGH 8.8
CVE-2025-25053
OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS comma…
Mitigation only
CRITICAL 9.8
CVE-2025-27797
OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be…
Mitigation only
HIGH 8.4
CVE-2025-30286
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co…
Coldfusion
Mitigation only
HIGH 8.2
CVE-2025-30289EPSS 5%
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co…
Coldfusion
Mitigation only
MEDIUM 6.5
CVE-2025-27078
A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying…
Mitigation only
MEDIUM 6.0
CVE-2025-27079
A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacke…
Mitigation only
HIGH 7.2
CVE-2024-54024
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before…
Fortiisolator
2.4.7+
MEDIUM 6.7
CVE-2024-54025
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI be…
Fortiisolator
2.4.7+
HIGH 7.2
CVE-2024-41789
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the l…
7kt Pac1260 Data Manager Firmware
Mitigation only
HIGH 7.2
CVE-2024-41790
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the r…
7kt Pac1260 Data Manager Firmware
Mitigation only
HIGH 7.2
CVE-2024-41788
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the i…
7kt Pac1260 Data Manager Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-3363
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS c…
Mitigation only