Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4203

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-3…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4204

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DN…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4205

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4197EPSS 18%

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Unclassified MEDIUM 5.3
CVE-2026-4198

A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. Affected by this vulnerability is the function getGitChanges of the f…

Patch available
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.3
CVE-2026-4199

A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file sr…

Patch available
Fix from $1,600 2026-03-16
Dnr 202l Firmware CRITICAL 9.8
CVE-2026-4195

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DN…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Dns 1550 04 Firmware CRITICAL 9.8
CVE-2026-4196

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS…

Fix: after 2026-02-05
Fix from $2,300 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4192

A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setupToolHandlers of the file src…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4170

A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/manage…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4163

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4164

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of t…

Mitigation only
Fix from $2,300 2026-03-16
365 Copilot HIGH 7.1
CVE-2026-26133

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Fix: 2.2.260210.21290750 / 2.106+
Fix from $1,950 2026-03-16
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26793

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26795

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26791

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26792

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe…

Mitigation only
Fix from $2,300 2026-03-12
Unclassified MEDIUM 5.3
CVE-2026-3964

A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Cha…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified MEDIUM 5.3
CVE-2026-3959

A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js…

Mitigation only
Fix from $1,600 2026-03-11
Splunk HIGH 7.2
CVE-2026-20163

In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.…

Fix: 9.3.10 / 9.3.2411.124+
Fix from $1,950 2026-03-11
Openclaw HIGH 7.8
CVE-2026-32063

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled …

Fix: 2026.2.21+
Fix from $1,950 2026-03-11
Unclassified HIGH 7.3
CVE-2026-3943EPSS 39%

A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The man…

Mitigation only
Fix from $1,950 2026-03-11
Arubaos Cx HIGH 7.2
CVE-2026-23815

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command …

Fix: after 10.17.0001
Fix from $1,950 2026-03-11
Arubaos Cx HIGH 8.8
CVE-2026-23814

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicio…

Fix: after 10.17.0001
Fix from $1,950 2026-03-11
Enterprise Server HIGH 8.8
CVE-2026-3854EPSS 34%

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to …

Fix: 3.14.24 / 3.15.19+
Fix from $1,950 2026-03-10
Jflow CRITICAL 9.8
CVE-2026-3813

A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerability is the function Calcula…

Mitigation only
Fix from $2,300 2026-03-09
Cf Ac100 Firmware HIGH 7.2
CVE-2026-3798EPSS 15%

A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET&section=pi…

No fix yet
Fix from $1,950 2026-03-09
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3704

A vulnerability has been found in Wavlink NU516U1 251208. This vulnerability affects the function sub_405B2C of the file /cgi-bin/firewall.cgi of the…

No fix yet
Fix from $1,950 2026-03-08
N300rh Firmware CRITICAL 9.8
CVE-2026-3696

A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-03-08
Unclassified MEDIUM 6.3
CVE-2026-3680

A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknown functionality of the file b…

Patch available
Fix from $1,600 2026-03-07