Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Unclassified MEDIUM 6.3
CVE-2026-12815

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation le…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12814

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_co…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.3
CVE-2026-12810

A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the comp…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.3
CVE-2026-12809

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the c…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.3
CVE-2026-12807

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Hand…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.3
CVE-2026-12808

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Reque…

Mitigation only
Fix from $1,600 2026-06-21
365 Copilot HIGH 7.5
CVE-2026-42895

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…

Mitigation only
Fix from $1,950 2026-06-19
Pgadmin 4 HIGH 8.8
CVE-2026-12045

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute …

Fix: 9.16+
Fix from $1,950 2026-06-19
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38714

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38715

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38716

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38717

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Unclassified HIGH 8.8
CVE-2024-24909

Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authen…

Mitigation only
Fix from $1,950 2026-06-16
Unclassified HIGH 7.8
CVE-2025-56814

A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metachar…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 5.5
CVE-2026-12223

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file …

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.3
CVE-2026-12219

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnos…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.2
CVE-2026-12197

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2026-12187

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /…

Mitigation only
Fix from $1,950 2026-06-14
Unclassified HIGH 8.8
CVE-2026-12186

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor o…

Mitigation only
Fix from $1,950 2026-06-14
Openclaw HIGH 8.8
CVE-2026-53822

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers …

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Kitty HIGH 8.8
CVE-2026-42850

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error.…

Fix: 0.47.0+
Fix from $1,950 2026-06-12
Unclassified HIGH 7.8
CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45558

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi…

Mitigation only
Fix from $2,300 2026-06-10
Unclassified HIGH 8.8
CVE-2026-11572

Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user inpu…

Patch available
Fix from $1,950 2026-06-09
Unclassified HIGH 8.8
CVE-2026-11556

A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the co…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified MEDIUM 5.3
CVE-2026-11487

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component V…

Patch available
Fix from $1,600 2026-06-08
Unclassified MEDIUM 5.0
CVE-2026-11455

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/u…

Mitigation only
Fix from $1,600 2026-06-07
Unclassified HIGH 7.3
CVE-2026-11451

A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. …

Mitigation only
Fix from $1,950 2026-06-07
Unclassified HIGH 7.3
CVE-2026-11452

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_…

Mitigation only
Fix from $1,950 2026-06-07
Unclassified MEDIUM 6.3
CVE-2026-11449

A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of …

Mitigation only
Fix from $1,600 2026-06-07