Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2026-6987 A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher … Picoclaw after 0.2.4 Fix from $2,3002026-04-25 HIGH 7.3 CVE-2026-6980 A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of … Mitigation only Fix from $1,9502026-04-25 CRITICAL 9.8 CVE-2026-41265 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth… Flowise 3.1.0+ Fix from $2,3002026-04-23 MEDIUM 6.5 CVE-2026-31169 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter t… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31173 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval paramet… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31162 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31163 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu paramete… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31166 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the hour parameter t… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31167 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter t… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31168 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour paramete… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31179 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort paramet… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31159 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password paramet… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31160 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider paramet… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31164 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu paramet… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31165 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31171 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31172 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter t… A3300r Firmware No fix yet Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-31174 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable par… A3300r Firmware No fix yet Fix from $1,6002026-04-23 CRITICAL 9.8 CVE-2026-31175 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 MEDIUM 6.5 CVE-2026-31176 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parame… A3300r Firmware No fix yet Fix from $1,6002026-04-23 CRITICAL 9.8 CVE-2026-41304 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel… Avideo after 29.0 Fix from $2,3002026-04-22 MEDIUM 6.3 CVE-2026-6799 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config… Mitigation only Fix from $1,6002026-04-21 HIGH 7.3 CVE-2026-38834 Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vu… W30e Firmware No fix yet Fix from $1,9502026-04-21 CRITICAL 9.8 CVE-2026-38835 Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName… W30e Firmware Mitigation only Fix from $2,3002026-04-21 HIGH 8.8 CVE-2026-39866 Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.… Lawnchair after 15.0.0 Fix from $1,9502026-04-21 HIGH 7.2 CVE-2026-4048 OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to ex… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-3517EPSS 18% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” p… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-3518EPSS 20% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to e… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-3519 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” pe… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6576 A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanage… Mitigation only Fix from $1,6002026-04-19