Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1412

A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown funct…

Fix: after 3.0.12
Fix from $2,300 2026-01-26
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0779

ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2026-01-23
Orval CRITICAL 9.8
CVE-2026-24132

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 th…

Fix: 7.20.0 / 8.0.3+
Fix from $2,300 2026-01-23
Copilot Studio HIGH 7.5
CVE-2026-21520

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …

Mitigation only
Fix from $1,950 2026-01-22
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1324EPSS 6%

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon…

Fix: after 3.0.12
Fix from $2,300 2026-01-22
Nr1800x Firmware HIGH 8.8
CVE-2026-1326

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cste…

No fix yet
Fix from $1,950 2026-01-22
Nr1800x Firmware HIGH 8.8
CVE-2026-1327

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /c…

No fix yet
Fix from $1,950 2026-01-22
Unclassified MEDIUM 5.9
CVE-2025-15366

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containi…

Patch available
Fix from $1,600 2026-01-20
Unclassified MEDIUM 5.9
CVE-2025-15367

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containin…

Patch available
Fix from $1,600 2026-01-20
Orval CRITICAL 9.8
CVE-2026-23947

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul…

Fix: 7.19.0 / 8.0.2+
Fix from $2,300 2026-01-20
Online Store Management System HIGH 7.3
CVE-2026-1192EPSS 6%

A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of th…

No fix yet
Fix from $1,950 2026-01-19
Lr350 Firmware HIGH 8.8
CVE-2026-1150

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.c…

No fix yet
Fix from $1,950 2026-01-19
Lr350 Firmware HIGH 8.8
CVE-2026-1149

A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.…

No fix yet
Fix from $1,950 2026-01-19
Dir 823x Firmware CRITICAL 9.8
CVE-2026-1125EPSS 15%

A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings.…

Mitigation only
Fix from $2,300 2026-01-18
Kodbox HIGH 8.8
CVE-2026-1066EPSS 5%

A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the co…

Fix: after 1.61.10
Fix from $1,950 2026-01-17
Brpc CRITICAL 9.8
CVE-2025-60021EPSS 25%

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …

Fix: 1.15.0+
Fix from $2,300 2026-01-16
Diaview CRITICAL 9.8
CVE-2026-0975

Delta Electronics DIAView has Command Injection vulnerability.

Fix: 4.4.0+
Fix from $2,300 2026-01-16
Deno CRITICAL 9.8
CVE-2026-22864

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning…

Fix: 2.5.6+
Fix from $2,300 2026-01-15
Cursor CRITICAL 9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…

Fix: 2.3+
Fix from $2,300 2026-01-14
Arubaos HIGH 7.2
CVE-2025-37176

A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially af…

Fix: 8.10.0.21 / 8.13.1.1+
Fix from $1,950 2026-01-13
Unclassified CRITICAL 9.3
CVE-2026-22755EPSS 20%

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365…

Mitigation only
Fix from $2,300 2026-01-13
Orval CRITICAL 9.8
CVE-2026-22785

orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation l…

Fix: 7.18.0+
Fix from $2,300 2026-01-12
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15502EPSS 6%

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro…

Fix: after 3.0.8
Fix from $2,300 2026-01-10
Weknora HIGH 8.8
CVE-2026-22688

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injec…

Fix: 0.2.5+
Fix from $1,950 2026-01-10
Openproject HIGH 7.2
CVE-2026-22601

OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…

Fix: 16.6.2+
Fix from $1,950 2026-01-10
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15501EPSS 6%

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th…

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Operation And Maintenance Management System CRITICAL 9.8
CVE-2025-15500EPSS 6%

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file …

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Operation And Maintenance Management System CRITICAL 9.8
CVE-2025-15499EPSS 5%

A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o…

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Odis MEDIUM 6.5
CVE-2025-66715

A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.

Fix: after 1.8.4
Fix from $1,600 2026-01-09
Dir 895la1 Firmware CRITICAL 9.8
CVE-2025-69542EPSS 9%

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease r…

Mitigation only
Fix from $2,300 2026-01-09