Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.9 CVE-2026-53533 aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-su… Fix unknown Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-24301 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose … Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-75094 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid… Fix unknown Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-75011 A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argum… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.4 CVE-2026-75007 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, whic… Fix unknown Fix from $4,0002026-08-17 HIGH 7.1 CVE-2026-75002 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure… Fix unknown Fix from $4,9002026-08-17 HIGH 7.4 CVE-2026-19982 A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-mana… Fix unknown Fix from $4,9002026-08-17 HIGH 8.3 CVE-2026-19983 A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown proce… Fix unknown Fix from $4,9002026-08-17 HIGH 7.4 CVE-2026-19981 A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.3 CVE-2026-19978 A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_proc… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.6 CVE-2026-19976 A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SE… Fix unknown Fix from $4,0002026-08-17 HIGH 7.4 CVE-2026-19963 A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulatio… Fix unknown Fix from $4,9002026-08-17 HIGH 7.4 CVE-2026-19962 A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipu… Fix unknown Fix from $4,9002026-08-17 HIGH 7.4 CVE-2026-19960 A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such man… No fix yet Fix from $4,9002026-08-16 HIGH 7.8 CVE-2026-50523 Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute … Powershell No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-19771 A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component … No fix yet Fix from $4,9002026-08-14 CRITICAL 9.8 CVE-2026-19747 A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fu… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.4 CVE-2026-73250 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenc… No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-68792 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate priv… 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65656 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute co… 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-49179 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex… Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.2 CVE-2026-47299 Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p… Azure Monitor Agent 1.43+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-47285 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose… Visual Studio Code No fix yet Fix from $4,0002026-08-11 HIGH 8.6 CVE-2026-73078 Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autolo… No fix yet Fix from $4,9002026-08-11 HIGH 7.3 CVE-2026-72913 Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated d… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.3 CVE-2026-72904 Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in … No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72869 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72736 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands v… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72735 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/applic… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-28672 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger… Ranger No fix yet Fix from $5,7502026-08-10