← Back to News Iceland Security Dashboard Browse all tags
T1059

Command/Scripting Interpreter

View on attack.mitre.org →

CVEs tagged with this technique (50)

CVE-2026-10520 🚨 CVSS 10.0 ivanti / standalone_sentry
CVE-2026-10520 is a critical OS Command Injection vulnerability (CWE-78) in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. It allows a remote un…
CVE-2026-1281 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulnerability …
CVE-2026-8398 🚨 CVSS 9.8 Daemon / Daemon Tools Lite
CVE-2026-8398 is a critical supply chain vulnerability (CWE-506) affecting DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, where attackers trojanize…
CVE-2026-45247 🚨 CVSS 9.8 Mirasvit / Mirasvit Full Page Cache Warmer
CVE-2026-45247 is a critical remote code execution vulnerability in Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12. The flaw stems from…
CVE-2026-25108 🚨 CVSS 8.8 Soliton Systems K.K / FileZen
CVE-2026-25108 is a command injection vulnerability in Soliton Systems K.K.'s FileZen product, specifically affecting the Antivirus Check Option when enabled. I…
CVE-2026-34197 🚨 CVSS 8.8 Apache / ActiveMQ
CVE-2026-34197 is a high-severity code injection vulnerability in Apache ActiveMQ (versions before 5.19.4 and 6.0.0-6.2.3) caused by improper input validation i…
CVE-2026-42271 🚨 CVSS 8.8 BerriAI / LiteLLM
CVE-2026-42271 is a command injection vulnerability in LiteLLM versions 1.74.2 through 1.83.6 affecting the MCP server preview endpoints. The flaw allows any au…
CVE-2026-22719 🚨 CVSS 8.1 Broadcom / VMware Aria Operations
CVE-2026-22719 is a high-severity command injection vulnerability (CWE-77) in VMware Aria Operations that allows unauthenticated remote code execution during su…
CVE-2026-20245 🚨 CVSS 7.8 Cisco / Catalyst SD-WAN Manager
CVE-2026-20245 is a command injection vulnerability in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) caused by insufficient validation of u…
CVE-2026-34926 🚨 CVSS 6.7 Trend Micro / Apex One
Trend Micro Apex One on-premise server contains a directory traversal vulnerability (CWE-23) allowing pre-authenticated local attackers with administrative acce…
CVE-2025-29635 🚨 D-Link / DIR-823X
CVE-2025-29635 is a command injection vulnerability (CWE-77) affecting D-Link DIR-823X firmware versions 240126 and 240802, allowing authorized attackers to exe…
CVE-2026-33017 🚨 Langflow / Langflow
Langflow versions prior to 1.9.0 contain a critical remote code execution vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. The flaw a…
CVE-2025-68613 🚨 n8n / n8n
CVE-2025-68613 is a critical Remote Code Execution vulnerability in n8n versions 0.211.0 through 1.120.3, 1.121.0, and 1.121.9, caused by insufficient isolation…
CVE-2025-26399 🚨 SolarWinds / Web Help Desk
SolarWinds Web Help Desk contains a critical unauthenticated AjaxProxy deserialization vulnerability (CVE-2025-26399) that allows remote code execution on the h…
CVE-2022-20775 🚨 Cisco / SD-WAN
CVE-2022-20775 is a high-severity vulnerability (CVSS 7.8) in Cisco SD-WAN Software affecting the CLI due to improper access controls. It allows an authenticate…
CVE-2024-7694 🚨 TeamT5 / ThreatSonar Anti-Ransomware
CVE-2024-7694 affects TeamT5's ThreatSonar Anti-Ransomware, allowing remote attackers with administrator privileges to upload malicious files that execute arbit…
CVE-2026-1731 🚨 BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-1731 is a critical remote code execution vulnerability in BeyondTrust Remote Support (RS) and older versions of Privileged Remote Access (PRA). It allo…
CVE-2025-11953 🚨 React Native Community / CLI
CVE-2025-11953 is a critical command injection vulnerability (CVSS 9.8) in the Metro Development Server provided by the React Native Community CLI, which binds …
CVE-2026-24423 🚨 SmarterTools / SmarterMail
CVE-2026-24423 is a critical remote code execution vulnerability in SmarterTools SmarterMail versions prior to build 9511, classified under CWE-306. It allows u…
CVE-2025-64328 🚨 Sangoma / FreePBX
Sangoma FreePBX Endpoint Manager versions 17.0.2.36 through 17.0.3 contain a post-authentication command injection vulnerability in the filestore module's testc…
CVE-2025-40551 🚨 SolarWinds / Web Help Desk
SolarWinds Web Help Desk contains a critical untrusted data deserialization vulnerability (CWE-502) that allows remote code execution without authentication. Th…
CVE-2025-20393 🚨 Cisco / Multiple Products
CVE-2025-20393 is a critical remote code execution vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cis…
CVE-2025-66644 🚨 Array Networks / ArrayOS AG
CVE-2025-66644 is a command injection vulnerability in Array Networks ArrayOS AG versions prior to 9.4.5.9, classified under CWE-78. The vulnerability has a CVS…
CVE-2025-48703 🚨 CWP / Control Web Panel
CVE-2025-48703 is a critical remote code execution vulnerability in Control Web Panel (CWP) versions prior to 0.9.8.1205, classified under CWE-78. It allows una…
CVE-2025-24893 🚨 XWiki / Platform
CVE-2025-24893 is a critical remote code execution vulnerability in XWiki Platform affecting versions prior to 15.10.11, 16.4.1, and 16.5.0RC1. It allows unauth…
CVE-2014-6278 🚨 GNU / GNU Bash
CVE-2014-6278 is a command injection vulnerability in GNU Bash through version 4.3 bash43-026, classified under CWE-78. It allows remote attackers to execute ar…
CVE-2025-4008 🚨 Smartbedded / Meteobridge
CVE-2025-4008 affects the Meteobridge web interface, a system for managing weather station data collection via CGI shell scripts and C. The vulnerability allows…
CVE-2025-53690 🚨 Sitecore / Multiple Products
CVE-2025-53690 is a critical deserialization vulnerability (CWE-502) in Sitecore Experience Manager (XM) and Experience Platform (XP) versions through 9.0, allo…
CVE-2025-8876 🚨 N-able / N-Central
CVE-2025-8876 is a command injection vulnerability in N-able N-central versions prior to 2025.3.1, stemming from improper input validation. The vulnerability is…
CVE-2025-49704 🚨 Microsoft / SharePoint
CVE-2025-49704 is a high-severity code injection vulnerability (CWE-94) in Microsoft Office SharePoint, allowing an authorized attacker to execute code over a n…
CVE-2025-47812 🚨 Wing FTP Server / Wing FTP Server
CVE-2025-47812 is a critical remote code execution vulnerability in Wing FTP Server versions prior to 7.4.4, caused by mishandling of null bytes in web interfac…
CVE-2025-24016 🚨 Wazuh / Wazuh Server
CVE-2025-24016 is a critical remote code execution vulnerability in Wazuh Server versions 4.4.0 through 4.9.1 caused by unsafe deserialization of DistributedAPI…
CVE-2025-32433 🚨 Erlang / Erlang/OTP
CVE-2025-32433 is a critical remote code execution vulnerability in Erlang/OTP SSH servers affecting versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2…
CVE-2025-3935 🚨 ConnectWise / ScreenConnect
CVE-2025-3935 affects ConnectWise ScreenConnect versions 25.2.3 and earlier, involving a ViewState code injection vulnerability (CWE-502) that can lead to remot…
CVE-2023-39780 🚨 ASUS / RT-AX55 Routers
CVE-2023-39780 is a high-severity command injection vulnerability (CWE-78) affecting ASUS RT-AX55 routers running firmware version 3.0.0.4.386.51598, allowing a…
CVE-2024-12987 🚨 DrayTek / Vigor Routers
CVE-2024-12987 is a critical command injection vulnerability in DrayTek Vigor2960 and Vigor300B routers running firmware version 1.5.1.4, affecting the Web Mana…
CVE-2025-32756 🚨 Fortinet / Multiple Products
CVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting multiple versions of Fortinet FortiCamera, FortiMail, FortiNDR, FortiRecorder, …
CVE-2024-11120 🚨 GeoVision / Multiple Devices
CVE-2024-11120 is a critical OS Command Injection vulnerability (CWE-78) affecting End-of-Life GeoVision devices, allowing unauthenticated remote attackers to e…
CVE-2024-6047 🚨 GeoVision / Multiple Devices
CVE-2024-6047 is a critical command injection vulnerability (CWE-78) affecting multiple End-of-Life GeoVision devices, allowing unauthenticated remote attackers…
CVE-2025-3248 🚨 Langflow / Langflow
CVE-2025-3248 is a critical remote code injection vulnerability in Langflow versions prior to 1.3.0, affecting the /api/v1/validate/code endpoint. It carries a …
CVE-2023-44221 🚨 SonicWall / SMA100 Appliances
CVE-2023-44221 is a command injection vulnerability in the SonicWall SMA100 SSL-VPN management interface, classified under CWE-78. It allows a remote authentica…
CVE-2025-1976 🚨 Broadcom / Brocade Fabric OS
CVE-2025-1976 affects Broadcom Brocade Fabric OS versions 9.1.0 through 9.1.1d6, allowing a local user with admin privileges to execute arbitrary code with full…
CVE-2021-20035 🚨 SonicWall / SMA100 Appliances
CVE-2021-20035 is a command injection vulnerability (CWE-78) in the SonicWall SMA100 management interface, allowing remote authenticated attackers to inject arb…
CVE-2025-30406 🚨 Gladinet / CentreStack
CVE-2025-30406 is a critical deserialization vulnerability in Gladinet CentreStack versions through 16.1.10296.56315, caused by a hardcoded machineKey that allo…
CVE-2025-24813 🚨 Apache / Tomcat
CVE-2025-24813 is a critical vulnerability in Apache Tomcat versions 11.0.0-M1 through 11.0.2, 10.1.0-M1 through 10.1.34, and 9.0.0.M1 through 9.0.98, allowing …
CVE-2019-9875 🚨 Sitecore / CMS and Experience Platform (XP)
CVE-2019-9875 is a high-severity deserialization vulnerability (CWE-502) in the anti-CSRF module of Sitecore CMS and Experience Platform through version 9.1. It…
CVE-2025-21590 🚨 Juniper / Junos OS
CVE-2025-21590 is a Medium severity (CVSS 4.4) Improper Isolation or Compartmentalization vulnerability (CWE-653) in the Juniper Networks Junos OS kernel. It al…
CVE-2025-22224 🚨 VMware / ESXi and Workstation
CVE-2025-22224 is a critical race-condition vulnerability (CWE-367) in VMware ESXi and Workstation that allows an out-of-bounds write via a TOCTOU flaw. A local…
CVE-2024-4885 🚨 Progress / WhatsUp Gold
CVE-2024-4885 is a critical Remote Code Execution vulnerability in Progress WhatsUp Gold versions prior to 2023.1.3, allowing unauthenticated attackers to execu…
CVE-2022-43769 🚨 Hitachi Vantara / Pentaho Business Analytics (BA) Server
CVE-2022-43769 is a HIGH severity vulnerability (CVSS 8.8) in Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.1 and 9.3.0.2, including…

Articles tagged with T1059 (30)

CRITICAL
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Dark Reading · 2026-06-12
CRITICAL
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
Ars Technica Security · 2026-06-12
CRITICAL
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
The Hacker News · 2026-06-12
HIGH
Over 400 Arch Linux packages compromised to push rootkit, infostealer
BleepingComputer · 2026-06-12
CRITICAL
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
The Hacker News · 2026-06-12
HIGH
Iranian Cyber Group Handala Claims Cal Water Hack
SecurityWeek · 2026-06-12
CRITICAL
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
SecurityWeek · 2026-06-12
HIGH
OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor
SC Media · 2026-06-11
HIGH
OnyxC2 stealer sold as a service targets over 210 applications
SC Media · 2026-06-11
CRITICAL
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
BleepingComputer · 2026-06-11
CRITICAL
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
Google Threat Intelligence · 2026-06-11
HIGH
Cybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT Malware
Infosecurity Magazine · 2026-06-11
HIGH
OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
SecurityWeek · 2026-06-11
HIGH
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
Infosecurity Magazine · 2026-06-11
HIGH
[NEU] [hoch] Jenkins: Mehrere Schwachstellen
BSI Germany · 2026-06-11
CRITICAL
[NEU] [hoch] n8n: Mehrere Schwachstellen
BSI Germany · 2026-06-11
MEDIUM
Trust No Skill: Integrity Verification for AI Agent Supply Chains
Unit 42 · 2026-06-11
HIGH
Angry bug hunter with Microsoft beef drops new Windows 0-day
The Register Security · 2026-06-10
HIGH
Free Spotify Premium hacks on social media are spreading infostealers
Malwarebytes Labs · 2026-06-10
HIGH
New SilabRAT Trojan Hijacks Sessions to Steal Crypto
Infosecurity Magazine · 2026-06-10
MEDIUM
Mini Shai-Hulud ‘Hades’ variant affects 23 PyPI package versions
SC Media · 2026-06-10
CRITICAL
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
The Hacker News · 2026-06-10
HIGH
GitHub disables Microsoft repos pushing password-stealing malware
BleepingComputer · 2026-06-09
CRITICAL
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Dark Reading · 2026-06-09
HIGH
Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation
SecurityWeek · 2026-06-09
CRITICAL
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
The Hacker News · 2026-06-09
MEDIUM
WinGet - Code Execution, Persistence and Detection Strategies
Reddit r/netsec · 2026-06-09
HIGH
[NEU] [hoch] VMware Tanzu Spring Framework: Mehrere Schwachstellen
BSI Germany · 2026-06-09
CRITICAL
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
The Hacker News · 2026-06-09
MEDIUM
AI worm prototype shows attackers don’t need Mythos to take over your network
CSO Online · 2026-06-09