Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Nemo HIGH 7.8
CVE-2025-33246

NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supply…

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33249

NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could …

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Unclassified HIGH 7.3
CVE-2026-2629

A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the f…

Mitigation only
Fix from $1,950 2026-02-17
Smartfabric Os10 HIGH 7.2
CVE-2026-22284

Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements used in a Command ('Command Inje…

Fix: 10.5.6.12+
Fix from $1,950 2026-02-17
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-2615EPSS 12%

A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewal…

Fix: after 2025-12-08
Fix from $1,950 2026-02-17
Unclassified MEDIUM 6.3
CVE-2026-2560

A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoRes…

Mitigation only
Fix from $1,600 2026-02-16
Unclassified MEDIUM 6.3
CVE-2026-2548

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_…

Mitigation only
Fix from $1,600 2026-02-16
Unclassified HIGH 7.3
CVE-2026-2544

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipu…

Mitigation only
Fix from $1,950 2026-02-16
Cf E4 Firmware HIGH 7.2
CVE-2026-2537EPSS 24%

A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_tim…

No fix yet
Fix from $1,950 2026-02-16
Cf N1 Firmware HIGH 8.8
CVE-2026-2535EPSS 14%

A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&se…

No fix yet
Fix from $1,950 2026-02-16
Unclassified HIGH 7.3
CVE-2026-2533

A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing …

Mitigation only
Fix from $1,950 2026-02-16
Cf N1 Firmware HIGH 8.8
CVE-2026-2534EPSS 13%

A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=S…

No fix yet
Fix from $1,950 2026-02-16
Wl Wn579a3 Firmware HIGH 8.8
CVE-2026-2530EPSS 8%

A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipul…

Fix: after 2021-02-19
Fix from $1,950 2026-02-16
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2026-2529EPSS 8%

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wirel…

Fix: after 2021-02-19
Fix from $2,300 2026-02-16
Wl Wn579a3 Firmware HIGH 8.8
CVE-2026-2526EPSS 8%

A vulnerability was found in Wavlink WL-WN579A3 up to 20210219. This impacts the function multi_ssid of the file /cgi-bin/wireless.cgi. Performing a …

Fix: after 2021-02-19
Fix from $1,950 2026-02-16
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2026-2527EPSS 8%

A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a mani…

Fix: after 2021-02-19
Fix from $2,300 2026-02-16
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2026-2528EPSS 8%

A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-…

Fix: after 2021-02-19
Fix from $2,300 2026-02-16
Open Source Point Of Sale HIGH 7.4
CVE-2025-70093

An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

Patch available
Fix from $1,950 2026-02-13
Emp3r0r CRITICAL 9.9
CVE-2026-26068

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is ac…

Fix: 3.21.1+
Fix from $2,300 2026-02-12
Ipados MEDIUM 5.5
CVE-2026-20675

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Mealie MEDIUM 5.4
CVE-2025-70296

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary H…

Fix: 3.8.0+
Fix from $1,600 2026-02-11
Visual Studio Code HIGH 8.8
CVE-2026-21518

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized a…

Fix: 1.109.2+
Fix from $1,950 2026-02-10
Confcom MEDIUM 6.7
CVE-2026-21522

Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate…

Fix: 1.2.8+
Fix from $1,600 2026-02-10
Github Copilot HIGH 7.8
CVE-2026-21516

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code…

Fix: 1.5.63-243+
Fix from $1,950 2026-02-10
Visual Studio 2022 HIGH 8.8
CVE-2026-21256

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…

Fix: 17.14.26+
Fix from $1,950 2026-02-10
Visual Studio 2022 HIGH 8.0
CVE-2026-21257

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker…

Fix: 17.14.26+
Fix from $1,950 2026-02-10
Windows Notepad HIGH 7.8
CVE-2026-20841EPSS 12%

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute…

Fix: 11.2510+
Fix from $1,950 2026-02-10
Dcs 931l Firmware HIGH 7.2
CVE-2026-2260

A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argu…

Fix: after 1.13.00
Fix from $1,950 2026-02-10
Super Linter HIGH 8.8
CVE-2026-25761

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vul…

Fix: 8.3.1+
Fix from $1,950 2026-02-09
Dcs 931l Firmware HIGH 7.2
CVE-2026-2227EPSS 6%

A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation o…

Fix: after 1.13.00
Fix from $1,950 2026-02-09