Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Picoclaw CRITICAL 9.8
CVE-2026-6987

A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher …

Fix: after 0.2.4
Fix from $2,300 2026-04-25
Unclassified HIGH 7.3
CVE-2026-6980

A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of …

Mitigation only
Fix from $1,950 2026-04-25
Flowise CRITICAL 9.8
CVE-2026-41265

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31169

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter t…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31173

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval paramet…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31162

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31163

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu paramete…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31166

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the hour parameter t…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31167

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter t…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31168

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour paramete…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31179

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort paramet…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31159

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password paramet…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31160

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider paramet…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31164

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu paramet…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31165

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31171

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31172

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter t…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31174

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable par…

No fix yet
Fix from $1,600 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31175

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param…

Mitigation only
Fix from $2,300 2026-04-23
A3300r Firmware MEDIUM 6.5
CVE-2026-31176

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parame…

No fix yet
Fix from $1,600 2026-04-23
Avideo CRITICAL 9.8
CVE-2026-41304

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel…

Fix: after 29.0
Fix from $2,300 2026-04-22
Unclassified MEDIUM 6.3
CVE-2026-6799

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config…

Mitigation only
Fix from $1,600 2026-04-21
W30e Firmware HIGH 7.3
CVE-2026-38834

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vu…

No fix yet
Fix from $1,950 2026-04-21
W30e Firmware CRITICAL 9.8
CVE-2026-38835

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName…

Mitigation only
Fix from $2,300 2026-04-21
Lawnchair HIGH 8.8
CVE-2026-39866

Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.…

Fix: after 15.0.0
Fix from $1,950 2026-04-21
Connection Manager For Objectscale HIGH 7.2
CVE-2026-4048

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to ex…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Connection Manager For Objectscale HIGH 7.2
CVE-2026-3517EPSS 18%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” p…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Connection Manager For Objectscale HIGH 7.2
CVE-2026-3518EPSS 20%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to e…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Connection Manager For Objectscale HIGH 7.2
CVE-2026-3519

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” pe…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6576

A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanage…

Mitigation only
Fix from $1,600 2026-04-19