Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified MEDIUM 5.3
CVE-2026-16763

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js …

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.4
CVE-2026-47670

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid …

No fix yet
Fix from $2,300 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16733

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16735

A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file in…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16631

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component packa…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16630

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16629

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/loc…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16628

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin En…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.5
CVE-2026-16492

A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/g…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.0
CVE-2026-16488

A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/conf…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16489

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the comp…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.5
CVE-2026-47690

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbb…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.3
CVE-2026-47708

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` A…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 7.2
CVE-2026-44879

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injec…

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.3
CVE-2026-16448

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.0
CVE-2026-16133

A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executi…

No fix yet
Fix from $1,600 2026-07-18
Surrealdb HIGH 8.0
CVE-2025-71392

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command.…

Fix: 2.0.5 / 2.1.5+
Fix from $1,950 2026-07-18
Unclassified CRITICAL 9.1
CVE-2026-52199

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

Mitigation only
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-30623EPSS 6%

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP serv…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2025-65720

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted H…

Mitigation only
Fix from $2,300 2026-07-15
Tabby HIGH 7.8
CVE-2026-46709

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/path…

Fix: 1.0.234+
Fix from $1,950 2026-07-15
Windows Admin Center HIGH 8.8
CVE-2026-56197

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute …

Fix: 2606+
Fix from $1,950 2026-07-14
Copilot HIGH 7.1
CVE-2026-55145

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampe…

Mitigation only
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-50488

Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker t…

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-58635

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elev…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Visual Studio Code HIGH 8.4
CVE-2026-50520

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute …

Fix: 1.128.1+
Fix from $1,950 2026-07-14
365 Copilot CRITICAL 9.6
CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $2,300 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-15669

A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go …

Mitigation only
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.3
CVE-2026-22095

The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22103

The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.

Mitigation only
Fix from $2,300 2026-07-13