Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Airflow HIGH 8.8
CVE-2026-30898

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be …

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Cx2 Lite Firmware HIGH 8.8
CVE-2026-35682

Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., startin…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified MEDIUM 6.7
CVE-2026-21709

A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

Mitigation only
Fix from $1,600 2026-04-17
Junie CRITICAL 9.8
CVE-2026-41153

In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

Fix: 252.549.29+
Fix from $2,300 2026-04-17
Unclassified HIGH 7.2
CVE-2026-6483EPSS 14%

A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. …

Mitigation only
Fix from $1,950 2026-04-17
Powerprotect Dp Series Appliance MEDIUM 6.7
CVE-2026-23779

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…

Fix: 2.7.9 / 7.13.1.50+
Fix from $1,600 2026-04-17
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-23778

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…

Fix: 2.7.9 / 7.13.1.50+
Fix from $1,950 2026-04-17
Identity Services Engine CRITICAL 9.9
CVE-2026-20186EPSS 6%

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…

Fix: 3.2.0+
Fix from $2,300 2026-04-15
Identity Services Engine Passive Identity Connector CRITICAL 9.9
CVE-2026-20147EPSS 12%

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…

Fix: 3.1.0+
Fix from $2,300 2026-04-15
Fuel Cms HIGH 8.3
CVE-2026-30461

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.ph…

No fix yet
Fix from $1,950 2026-04-15
Unclassified HIGH 8.0
CVE-2026-30615

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf proces…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified HIGH 7.3
CVE-2026-30616

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network re…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified HIGH 8.6
CVE-2026-30617

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attack…

Mitigation only
Fix from $1,950 2026-04-15
Agent Zero HIGH 8.6
CVE-2026-30624

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to de…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-30625

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M…

Patch available
Fix from $2,300 2026-04-15
Unclassified HIGH 8.4
CVE-2024-53412

Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote…

Mitigation only
Fix from $1,950 2026-04-15
Windows 10 1607 HIGH 7.8
CVE-2026-32183

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execu…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Github Copilot Chat MEDIUM 6.5
CVE-2026-23653

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att…

Fix: 0.37.3+
Fix from $1,600 2026-04-14
Unclassified HIGH 7.1
CVE-2026-4786

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.…

Patch available
Fix from $1,950 2026-04-13
Unclassified MEDIUM 5.3
CVE-2026-6219

A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of…

No fix yet
Fix from $1,600 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6195EPSS 14%

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the fil…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6158

A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of t…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6155

A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6156

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cst…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6154

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6139

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6140

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of …

Mitigation only
Fix from $2,300 2026-04-13
Unclassified MEDIUM 6.3
CVE-2026-6141

A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/To…

Patch available
Fix from $1,600 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6138

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6131

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-…

Mitigation only
Fix from $2,300 2026-04-12