Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2026-1412 A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown funct… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-26 HIGH 8.8 CVE-2026-0779 ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-24132 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 th… Orval 7.20.0 / 8.0.3+ Fix from $2,3002026-01-23 HIGH 7.5 CVE-2026-21520 Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through … Copilot Studio Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-1324EPSS 6% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-22 HIGH 8.8 CVE-2026-1326 A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cste… Nr1800x Firmware No fix yet Fix from $1,9502026-01-22 HIGH 8.8 CVE-2026-1327 A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /c… Nr1800x Firmware No fix yet Fix from $1,9502026-01-22 MEDIUM 5.9 CVE-2025-15366 The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containi… Patch available Fix from $1,6002026-01-20 MEDIUM 5.9 CVE-2025-15367 The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containin… Patch available Fix from $1,6002026-01-20 CRITICAL 9.8 CVE-2026-23947 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul… Orval 7.19.0 / 8.0.2+ Fix from $2,3002026-01-20 HIGH 7.3 CVE-2026-1192EPSS 6% A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of th… Online Store Management System No fix yet Fix from $1,9502026-01-19 HIGH 8.8 CVE-2026-1150 A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.c… Lr350 Firmware No fix yet Fix from $1,9502026-01-19 HIGH 8.8 CVE-2026-1149 A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.… Lr350 Firmware No fix yet Fix from $1,9502026-01-19 CRITICAL 9.8 CVE-2026-1125EPSS 15% A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings.… Dir 823x Firmware Mitigation only Fix from $2,3002026-01-18 HIGH 8.8 CVE-2026-1066EPSS 5% A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the co… Kodbox after 1.61.10 Fix from $1,9502026-01-17 CRITICAL 9.8 CVE-2025-60021EPSS 25% Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to … Brpc 1.15.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-0975 Delta Electronics DIAView has Command Injection vulnerability. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-22864 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning… Deno 2.5.6+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-22708 Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce… Cursor 2.3+ Fix from $2,3002026-01-14 HIGH 7.2 CVE-2025-37176 A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially af… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $1,9502026-01-13 CRITICAL 9.3 CVE-2026-22755EPSS 20% Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-22785 orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation l… Orval 7.18.0+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-15502EPSS 6% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-10 HIGH 8.8 CVE-2026-22688 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injec… Weknora 0.2.5+ Fix from $1,9502026-01-10 HIGH 7.2 CVE-2026-22601 OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut… Openproject 16.6.2+ Fix from $1,9502026-01-10 CRITICAL 9.8 CVE-2025-15501EPSS 6% A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15500EPSS 6% A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file … Operation And Maintenance Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15499EPSS 5% A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o… Operation And Maintenance Management System after 3.0.8 Fix from $2,3002026-01-09 MEDIUM 6.5 CVE-2025-66715 A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file. Odis after 1.8.4 Fix from $1,6002026-01-09 CRITICAL 9.8 CVE-2025-69542EPSS 9% A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease r… Dir 895la1 Firmware Mitigation only Fix from $2,3002026-01-09