Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified MEDIUM 6.3
CVE-2026-9363

A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of t…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified MEDIUM 6.3
CVE-2026-9361

A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Re…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified MEDIUM 6.3
CVE-2026-9359

A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of …

Mitigation only
Fix from $1,600 2026-05-24
Unclassified MEDIUM 6.3
CVE-2026-9347

A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the compo…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified MEDIUM 6.3
CVE-2026-9343

A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of…

Mitigation only
Fix from $1,600 2026-05-23
Unclassified MEDIUM 6.3
CVE-2026-9297

A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the comp…

Mitigation only
Fix from $1,600 2026-05-23
Unclassified MEDIUM 6.3
CVE-2026-9296

A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request…

Mitigation only
Fix from $1,600 2026-05-23
365 Copilot HIGH 7.5
CVE-2026-42827

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

Mitigation only
Fix from $1,950 2026-05-22
365 Copilot CRITICAL 9.3
CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…

Mitigation only
Fix from $2,300 2026-05-22
Power Pages CRITICAL 9.8
CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…

Mitigation only
Fix from $2,300 2026-05-22
Unclassified HIGH 8.1
CVE-2026-9277

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-esc…

Patch available
Fix from $1,950 2026-05-22
Unclassified HIGH 8.4
CVE-2026-2740

Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Au…

Mitigation only
Fix from $1,950 2026-05-21
Authoritative HIGH 8.6
CVE-2026-42000

Insufficient Validation of Names During AXFR

Fix: 4.9.15 / 5.0.5+
Fix from $1,950 2026-05-21
Unclassified CRITICAL 9.1
CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability vi…

No fix yet
Fix from $2,300 2026-05-21
Linux Imaging And Printing HIGH 7.8
CVE-2026-8632

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalati…

Fix: 3.26.4+
Fix from $1,950 2026-05-20
Smartfabric Storage Software MEDIUM 6.7
CVE-2026-35070

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injec…

Fix: 1.4.5+
Fix from $1,600 2026-05-20
Windows 11 24h2 MEDIUM 6.8
CVE-2026-45585

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this…

No fix yet
Fix from $1,600 2026-05-20
Unclassified HIGH 8.8
CVE-2025-57282

ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.

Mitigation only
Fix from $1,950 2026-05-18
Unclassified MEDIUM 6.3
CVE-2026-8774

A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request…

Mitigation only
Fix from $1,600 2026-05-18
Unclassified MEDIUM 6.3
CVE-2026-8777

A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the compon…

Mitigation only
Fix from $1,600 2026-05-18
Ai HIGH 7.5
CVE-2026-8767

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the…

Fix: after 3.0.97
Fix from $1,950 2026-05-17
Unclassified MEDIUM 6.3
CVE-2026-8753

A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/sour…

Mitigation only
Fix from $1,600 2026-05-17
Turborepo Language Server Protocol HIGH 7.8
CVE-2026-46508

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could e…

Fix: 2.9.14000+
Fix from $1,950 2026-05-15
Unclassified HIGH 7.3
CVE-2026-39054

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacke…

Mitigation only
Fix from $1,950 2026-05-15
Cfengine HIGH 7.3
CVE-2026-24712

Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

Fix: 3.21.8 / 3.24.3+
Fix from $1,950 2026-05-14
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-41953

A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify c…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-40698

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role c…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Domain Name System HIGH 8.7
CVE-2026-40061

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authent…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
T18 21k Firmware HIGH 7.2
CVE-2026-36741

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface…

No fix yet
Fix from $1,950 2026-05-13
Arubaos HIGH 8.8
CVE-2026-44871

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Syste…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12