Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified MEDIUM 6.9
CVE-2026-53533

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-su…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-24301

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75094

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75011

A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argum…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-75007

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, whic…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.1
CVE-2026-75002

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19982

A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-mana…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.3
CVE-2026-19983

A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown proce…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19981

A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-19978

A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_proc…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.6
CVE-2026-19976

A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SE…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19963

A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulatio…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19962

A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipu…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19960

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such man…

No fix yet
Fix from $4,900 2026-08-16
Powershell HIGH 7.8
CVE-2026-50523

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.2
CVE-2026-19771

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component …

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-19747

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fu…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-73250

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenc…

No fix yet
Fix from $4,000 2026-08-11
365 Apps HIGH 7.8
CVE-2026-68792

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate priv…

No fix yet
Fix from $4,900 2026-08-11
365 Apps HIGH 7.8
CVE-2026-65656

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute co…

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.8
CVE-2026-49179

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex…

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Azure Monitor Agent HIGH 7.2
CVE-2026-47299

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p…

Fix: 1.43+
Fix from $4,900 2026-08-11
Visual Studio Code MEDIUM 6.5
CVE-2026-47285

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.6
CVE-2026-73078

Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autolo…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.3
CVE-2026-72913

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated d…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-72904

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in …

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72869

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72736

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands v…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72735

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/applic…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-28672

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger…

No fix yet
Fix from $5,750 2026-08-10