Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified HIGH 7.3
CVE-2026-5012

A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing a manipulation can lead to os…

Mitigation only
Fix from $1,950 2026-03-28
Unclassified MEDIUM 5.3
CVE-2026-5007

A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file src/index.ts of the component…

Mitigation only
Fix from $1,600 2026-03-28
Flannel HIGH 8.8
CVE-2026-32241

Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users…

Fix: 0.28.2+
Fix from $1,950 2026-03-27
Unclassified HIGH 8.8
CVE-2026-4840EPSS 11%

A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cg…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 7.2
CVE-2026-4627

A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_mod…

Mitigation only
Fix from $1,950 2026-03-24
X6000r Firmware HIGH 8.8
CVE-2026-4611

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file …

Mitigation only
Fix from $1,950 2026-03-23
Unclassified CRITICAL 9.8
CVE-2026-4585

A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy…

Mitigation only
Fix from $2,300 2026-03-23
Mr9600 Firmware HIGH 8.8
CVE-2026-4558

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipu…

No fix yet
Fix from $1,950 2026-03-22
F453 Firmware HIGH 8.8
CVE-2026-4554

A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The …

No fix yet
Fix from $1,950 2026-03-22
Wl Wn578w2 Firmware MEDIUM 6.3
CVE-2026-4543EPSS 6%

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the componen…

No fix yet
Fix from $1,600 2026-03-22
Openclaw CRITICAL 9.8
CVE-2026-32052

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde…

Fix: 2026.2.24+
Fix from $2,300 2026-03-21
Dir 820lw Firmware CRITICAL 9.8
CVE-2026-4499

A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le…

Mitigation only
Fix from $2,300 2026-03-20
Unclassified MEDIUM 5.3
CVE-2026-4496

A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function ch…

Patch available
Fix from $1,600 2026-03-20
Wa300 Firmware CRITICAL 9.8
CVE-2026-4497

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-03-20
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15607

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit…

Mitigation only
Fix from $2,300 2026-03-20
Dir 513 Firmware HIGH 8.8
CVE-2026-4465

A flaw has been found in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formSysCmd. Executing a manipulation of…

No fix yet
Fix from $1,950 2026-03-20
Bing Images CRITICAL 9.8
CVE-2026-32194

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…

No fix yet
Fix from $2,300 2026-03-19
Sqlbot HIGH 8.8
CVE-2026-32622

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner…

Fix: 1.6.0+
Fix from $1,950 2026-03-19
Copilot HIGH 7.5
CVE-2026-26136

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …

Mitigation only
Fix from $1,950 2026-03-19
365 Copilot MEDIUM 5.3
CVE-2026-24299

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified HIGH 7.2
CVE-2026-22317

A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacker to send crafted HTTP POST r…

Mitigation only
Fix from $1,950 2026-03-18
Roxy Wi HIGH 8.8
CVE-2026-27811

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex…

Fix: 8.2.6.3+
Fix from $1,950 2026-03-18
Sterling B2b Integrator HIGH 7.5
CVE-2025-14031

IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,950 2026-03-17
Ac8 Firmware HIGH 7.2
CVE-2026-4253EPSS 7%

A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of …

No fix yet
Fix from $1,950 2026-03-16
Thinos HIGH 7.8
CVE-2026-23862

Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') …

Fix: 2602.10.0573+
Fix from $1,950 2026-03-16
Bl Wr9000 Firmware CRITICAL 9.8
CVE-2026-4228EPSS 12%

A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results …

Mitigation only
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4210

A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4206

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4207

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4209

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16