Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8228

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipu…

No fix yet
Fix from $1,950 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8229

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing …

No fix yet
Fix from $1,950 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8230

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipula…

No fix yet
Fix from $1,950 2026-05-10
Unclassified MEDIUM 6.3
CVE-2026-8217

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the c…

Mitigation only
Fix from $1,600 2026-05-10
Unclassified MEDIUM 5.3
CVE-2026-8210

A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Upda…

Mitigation only
Fix from $1,600 2026-05-09
Net\ CRITICAL 9.8
CVE-2026-42257

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::…

Fix: 0.4.24 / 0.5.14+
Fix from $2,300 2026-05-09
Net\ MEDIUM 5.3
CVE-2026-42258

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol argume…

Fix: 0.4.24 / 0.5.14+
Fix from $1,600 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8192

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Per…

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8191EPSS 5%

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulatio…

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8190EPSS 5%

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipu…

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8189

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. …

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8188EPSS 5%

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The mani…

No fix yet
Fix from $1,950 2026-05-09
Unclassified HIGH 8.7
CVE-2026-42453

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, the extractArch…

Mitigation only
Fix from $1,950 2026-05-08
Praisonai CRITICAL 9.8
CVE-2026-41497

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg…

Fix: 4.6.9+
Fix from $2,300 2026-05-08
Unclassified MEDIUM 6.3
CVE-2024-30167

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST reque…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 7.3
CVE-2024-45257

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server …

Mitigation only
Fix from $1,950 2026-05-08
Prusaslicer MEDIUM 5.3
CVE-2023-47268

In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the pr…

Fix: after 2.6.1
Fix from $1,600 2026-05-08
Openshift Ai HIGH 8.8
CVE-2026-42271 KEVEPSS 83%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

Fix: 1.83.7 / 2.25.8+
Fix from $1,950 2026-05-08
Electerm CRITICAL 9.8
CVE-2026-41500

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e…

Fix: 3.3.8+
Fix from $2,300 2026-05-08
Electerm CRITICAL 9.8
CVE-2026-41501

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e…

Fix: 3.3.8+
Fix from $2,300 2026-05-08
Miniclaw HIGH 8.8
CVE-2026-8112

A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the f…

Fix: after 2026-04-29
Fix from $1,950 2026-05-07
Copilot Chat HIGH 7.5
CVE-2026-33111

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $1,950 2026-05-07
Azure Cloud Shell CRITICAL 9.6
CVE-2026-35428

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…

Mitigation only
Fix from $2,300 2026-05-07
Iot Field Network Director MEDIUM 6.4
CVE-2026-20169

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low priv…

Fix: 5.0.0-117+
Fix from $1,600 2026-05-06
Unclassified HIGH 8.8
CVE-2025-31951

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling w…

Mitigation only
Fix from $1,950 2026-05-06
Claude Code HIGH 8.8
CVE-2026-40068

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its co…

Fix: 2.1.84+
Fix from $1,950 2026-05-05
Unclassified HIGH 7.2
CVE-2026-7833

A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-7823

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7812

A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the function git_operation of th…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7785

A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. T…

Mitigation only
Fix from $1,950 2026-05-05