Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 8.8 CVE-2026-30898 An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be … Airflow 3.2.0+ Fix from $1,9502026-04-18 HIGH 8.8 CVE-2026-35682 Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., startin… Cx2 Lite Firmware Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.7 CVE-2026-21709 A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement. Mitigation only Fix from $1,6002026-04-17 CRITICAL 9.8 CVE-2026-41153 In JetBrains Junie before 252.549.29 command execution was possible via malicious project file Junie 252.549.29+ Fix from $2,3002026-04-17 HIGH 7.2 CVE-2026-6483EPSS 14% A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. … Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.7 CVE-2026-23779 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.50+ Fix from $1,6002026-04-17 HIGH 7.2 CVE-2026-23778 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.50+ Fix from $1,9502026-04-17 CRITICAL 9.9 CVE-2026-20186EPSS 6% A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… Identity Services Engine 3.2.0+ Fix from $2,3002026-04-15 CRITICAL 9.9 CVE-2026-20147EPSS 12% A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin… Identity Services Engine Passive Identity Connector 3.1.0+ Fix from $2,3002026-04-15 HIGH 8.3 CVE-2026-30461 Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.ph… Fuel Cms No fix yet Fix from $1,9502026-04-15 HIGH 8.0 CVE-2026-30615 A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf proces… Mitigation only Fix from $1,9502026-04-15 HIGH 7.3 CVE-2026-30616 Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network re… Mitigation only Fix from $1,9502026-04-15 HIGH 8.6 CVE-2026-30617 LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attack… Mitigation only Fix from $1,9502026-04-15 HIGH 8.6 CVE-2026-30624 Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to de… Agent Zero Mitigation only Fix from $1,9502026-04-15 CRITICAL 9.8 CVE-2026-30625 Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M… Patch available Fix from $2,3002026-04-15 HIGH 8.4 CVE-2024-53412 Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote… Mitigation only Fix from $1,9502026-04-15 HIGH 7.8 CVE-2026-32183 Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execu… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-23653 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att… Github Copilot Chat 0.37.3+ Fix from $1,6002026-04-14 HIGH 7.1 CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.… Patch available Fix from $1,9502026-04-13 MEDIUM 5.3 CVE-2026-6219 A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of… No fix yet Fix from $1,6002026-04-13 CRITICAL 9.8 CVE-2026-6195EPSS 14% A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the fil… Mitigation only Fix from $2,3002026-04-13 HIGH 7.3 CVE-2026-6158 A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of t… Mitigation only Fix from $1,9502026-04-13 CRITICAL 9.8 CVE-2026-6155 A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6156 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cst… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6154 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6139 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6140 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of … Mitigation only Fix from $2,3002026-04-13 MEDIUM 6.3 CVE-2026-6141 A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/To… Patch available Fix from $1,6002026-04-13 CRITICAL 9.8 CVE-2026-6138 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6131 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-… Mitigation only Fix from $2,3002026-04-12