Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2026-8228 A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipu… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-10 HIGH 8.8 CVE-2026-8229 A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing … Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-10 HIGH 8.8 CVE-2026-8230 A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipula… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-10 MEDIUM 6.3 CVE-2026-8217 A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the c… Mitigation only Fix from $1,6002026-05-10 MEDIUM 5.3 CVE-2026-8210 A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Upda… Mitigation only Fix from $1,6002026-05-09 CRITICAL 9.8 CVE-2026-42257 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::… Net\ 0.4.24 / 0.5.14+ Fix from $2,3002026-05-09 MEDIUM 5.3 CVE-2026-42258 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol argume… Net\ 0.4.24 / 0.5.14+ Fix from $1,6002026-05-09 HIGH 8.8 CVE-2026-8192 A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Per… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-09 HIGH 8.8 CVE-2026-8191EPSS 5% A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulatio… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-09 HIGH 8.8 CVE-2026-8190EPSS 5% A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipu… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-09 HIGH 8.8 CVE-2026-8189 A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. … Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-09 HIGH 8.8 CVE-2026-8188EPSS 5% A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The mani… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-05-09 HIGH 8.7 CVE-2026-42453 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, the extractArch… Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-41497 PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg… Praisonai 4.6.9+ Fix from $2,3002026-05-08 MEDIUM 6.3 CVE-2024-30167 /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST reque… Mitigation only Fix from $1,6002026-05-08 HIGH 7.3 CVE-2024-45257 A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server … Mitigation only Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2023-47268 In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the pr… Prusaslicer after 2.6.1 Fix from $1,6002026-05-08 HIGH 8.8 CVE-2026-42271 KEVEPSS 83% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use… Openshift Ai 1.83.7 / 2.25.8+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-41500 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e… Electerm 3.3.8+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41501 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e… Electerm 3.3.8+ Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-8112 A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the f… Miniclaw after 2026-04-29 Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-33111 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker … Copilot Chat Mitigation only Fix from $1,9502026-05-07 CRITICAL 9.6 CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s… Azure Cloud Shell Mitigation only Fix from $2,3002026-05-07 MEDIUM 6.4 CVE-2026-20169 A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low priv… Iot Field Network Director 5.0.0-117+ Fix from $1,6002026-05-06 HIGH 8.8 CVE-2025-31951 HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling w… Mitigation only Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-40068 In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its co… Claude Code 2.1.84+ Fix from $1,9502026-05-05 HIGH 7.2 CVE-2026-7833 A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the… Mitigation only Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2026-7823 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cg… Mitigation only Fix from $2,3002026-05-05 HIGH 7.3 CVE-2026-7812 A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the function git_operation of th… Mitigation only Fix from $1,9502026-05-05 HIGH 7.3 CVE-2026-7785 A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. T… Mitigation only Fix from $1,9502026-05-05