Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified CRITICAL 9.8
CVE-2026-5850EPSS 16%

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of …

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-5851EPSS 14%

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi o…

Mitigation only
Fix from $2,300 2026-04-09
Dir 882 Firmware HIGH 7.2
CVE-2026-5844EPSS 5%

A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings …

No fix yet
Fix from $1,950 2026-04-09
Unclassified MEDIUM 5.3
CVE-2026-5833

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the f…

Patch available
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.3
CVE-2026-5831

A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the…

Patch available
Fix from $1,600 2026-04-09
Unclassified HIGH 7.3
CVE-2026-5802

A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation …

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.3
CVE-2026-5741

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_…

Mitigation only
Fix from $1,950 2026-04-07
Emissary CRITICAL 9.1
CVE-2026-35580

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-contr…

Fix: after 8.38.0
Fix from $2,300 2026-04-07
Mantaray Nm HIGH 8.0
CVE-2025-24818

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in …

Fix: 25r1-nm+
Fix from $1,950 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5692

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The m…

Mitigation only
Fix from $1,950 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5691

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. …

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5690

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. E…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5689

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5688

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 5.5
CVE-2026-5679

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5677

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. P…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5678

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cst…

Mitigation only
Fix from $1,950 2026-04-06
Dcmtk CRITICAL 9.8
CVE-2026-5663

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/a…

Fix: after 3.7.0
Fix from $2,300 2026-04-06
520w Firmware CRITICAL 9.8
CVE-2026-31059

A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to exec…

Mitigation only
Fix from $2,300 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5621

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.t…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5619

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of t…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5603

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/…

Patch available
Fix from $1,600 2026-04-05
Unclassified MEDIUM 5.3
CVE-2026-5602

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_…

Patch available
Fix from $1,600 2026-04-05
Ac10 Firmware HIGH 8.8
CVE-2026-5547

A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such mani…

Mitigation only
Fix from $1,950 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5532

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file s…

Mitigation only
Fix from $1,600 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5528

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Inter…

Mitigation only
Fix from $1,600 2026-04-05
Athena Odbc HIGH 7.8
CVE-2026-35558

Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor t…

Fix: 2.1.0.0+
Fix from $1,950 2026-04-03
Pymetasploit3 CRITICAL 9.8
CVE-2026-5463

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline charact…

Fix: after 1.0.6
Fix from $2,300 2026-04-03
Tew 657brm Firmware HIGH 8.8
CVE-2026-5353

A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. Performing a manipulation of t…

No fix yet
Fix from $1,950 2026-04-02
Tew 657brm Firmware HIGH 8.8
CVE-2026-5354

A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the file /setup.cgi. Executing a m…

No fix yet
Fix from $1,950 2026-04-02