Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.3 CVE-2026-5012 A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing a manipulation can lead to os… Mitigation only Fix from $1,9502026-03-28 MEDIUM 5.3 CVE-2026-5007 A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file src/index.ts of the component… Mitigation only Fix from $1,6002026-03-28 HIGH 8.8 CVE-2026-32241 Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users… Flannel 0.28.2+ Fix from $1,9502026-03-27 HIGH 8.8 CVE-2026-4840EPSS 11% A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cg… Mitigation only Fix from $1,9502026-03-26 HIGH 7.2 CVE-2026-4627 A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_mod… Mitigation only Fix from $1,9502026-03-24 HIGH 8.8 CVE-2026-4611 A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file … X6000r Firmware Mitigation only Fix from $1,9502026-03-23 CRITICAL 9.8 CVE-2026-4585 A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy… Mitigation only Fix from $2,3002026-03-23 HIGH 8.8 CVE-2026-4558 A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipu… Mr9600 Firmware No fix yet Fix from $1,9502026-03-22 HIGH 8.8 CVE-2026-4554 A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The … F453 Firmware No fix yet Fix from $1,9502026-03-22 MEDIUM 6.3 CVE-2026-4543EPSS 6% A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the componen… Wl Wn578w2 Firmware No fix yet Fix from $1,6002026-03-22 CRITICAL 9.8 CVE-2026-32052 OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde… Openclaw 2026.2.24+ Fix from $2,3002026-03-21 CRITICAL 9.8 CVE-2026-4499 A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le… Dir 820lw Firmware Mitigation only Fix from $2,3002026-03-20 MEDIUM 5.3 CVE-2026-4496 A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function ch… Patch available Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-4497 A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c… Wa300 Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2025-15607 A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit… Archer Ax53 Firmware Mitigation only Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-4465 A flaw has been found in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formSysCmd. Executing a manipulation of… Dir 513 Firmware No fix yet Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-32194 Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu… Bing Images No fix yet Fix from $2,3002026-03-19 HIGH 8.8 CVE-2026-32622 SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner… Sqlbot 1.6.0+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-26136 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose … Copilot Mitigation only Fix from $1,9502026-03-19 MEDIUM 5.3 CVE-2026-24299 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Mitigation only Fix from $1,6002026-03-19 HIGH 7.2 CVE-2026-22317 A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacker to send crafted HTTP POST r… Mitigation only Fix from $1,9502026-03-18 HIGH 8.8 CVE-2026-27811 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex… Roxy Wi 8.2.6.3+ Fix from $1,9502026-03-18 HIGH 7.5 CVE-2025-14031 IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.… Sterling B2b Integrator 6.1.2.8 / 6.2.0.5_2+ Fix from $1,9502026-03-17 HIGH 7.2 CVE-2026-4253EPSS 7% A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of … Ac8 Firmware No fix yet Fix from $1,9502026-03-16 HIGH 7.8 CVE-2026-23862 Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') … Thinos 2602.10.0573+ Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2026-4228EPSS 12% A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results … Bl Wr9000 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4210 A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326… Dnr 202l Firmware after 2026-02-05 Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4206 A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L… Dnr 202l Firmware after 2026-02-05 Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4207 A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS… Dnr 202l Firmware after 2026-02-05 Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4209 A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS… Dnr 202l Firmware after 2026-02-05 Fix from $2,3002026-03-16