Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified CRITICAL 9.3
CVE-2026-44257

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.…

Mitigation only
Fix from $2,300 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44865

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 8.8
CVE-2026-44866

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 8.8
CVE-2026-44867

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 8.8
CVE-2026-44868

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 8.8
CVE-2026-44869

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 8.8
CVE-2026-44870

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Syste…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44872

A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could a…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44854

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could al…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44853

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could al…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Unclassified HIGH 7.2
CVE-2026-8431

An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specif…

Mitigation only
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-23823

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injecti…

Fix: 8.10.0.0 / 8.12.0.7+
Fix from $1,950 2026-05-12
Outlook HIGH 7.5
CVE-2026-42893

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamper…

Fix: 5.2617.1+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.4
CVE-2026-43990

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command …

Patch available
Fix from $1,950 2026-05-12
Netweaver Application Server Abap MEDIUM 6.5
CVE-2026-40135

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 8.2
CVE-2026-34259

Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could a…

Mitigation only
Fix from $1,950 2026-05-12
Dir 816 Firmware HIGH 8.8
CVE-2026-8346

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argume…

No fix yet
Fix from $1,950 2026-05-12
Dir 816 Firmware HIGH 8.8
CVE-2026-8345

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /g…

No fix yet
Fix from $1,950 2026-05-11
Dir 816 Firmware HIGH 8.8
CVE-2026-8344

A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /gofor…

No fix yet
Fix from $1,950 2026-05-11
Unclassified HIGH 8.8
CVE-2026-36734

EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLA…

Mitigation only
Fix from $1,950 2026-05-11
Dcs 932l Firmware HIGH 7.3
CVE-2026-36983

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument Lig…

No fix yet
Fix from $1,950 2026-05-11
Dns 320 Firmware HIGH 7.2
CVE-2026-8271

A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp…

No fix yet
Fix from $1,950 2026-05-11
Dns 320 Firmware HIGH 7.2
CVE-2026-8272EPSS 6%

A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/web…

No fix yet
Fix from $1,950 2026-05-11
Dns 320 Firmware HIGH 7.2
CVE-2026-8273

A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the fi…

No fix yet
Fix from $1,950 2026-05-11
Ac6 Firmware HIGH 7.2
CVE-2026-8265

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFi…

No fix yet
Fix from $1,950 2026-05-11
Ac6 Firmware HIGH 8.8
CVE-2026-8264

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan…

No fix yet
Fix from $1,950 2026-05-11
Ac10u Firmware CRITICAL 9.8
CVE-2026-8263

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtr…

Mitigation only
Fix from $2,300 2026-05-11
Ac6 Firmware HIGH 7.2
CVE-2026-8259

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component …

No fix yet
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.5
CVE-2026-8235

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the…

Patch available
Fix from $1,600 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8227

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation c…

No fix yet
Fix from $1,950 2026-05-10