Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.2 CVE-2026-18811 A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the a… No fix yet Fix from $1,9502026-08-04 HIGH 7.2 CVE-2026-18812 A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-18787 A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2025-29296 H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-18685 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the com… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-18686 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the … No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-18684 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the compo… No fix yet Fix from $2,3002026-08-03 HIGH 7.3 CVE-2026-18641 A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the fu… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-18614 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18615 A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-b… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18616 A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18612 A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18602 A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc o… No fix yet Fix from $2,3002026-08-03 HIGH 8.8 CVE-2026-18600 A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-18601 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon… No fix yet Fix from $2,3002026-08-03 HIGH 8.8 CVE-2026-18598 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-h… No fix yet Fix from $1,9502026-08-03 HIGH 8.0 CVE-2026-18599 A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/lo… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.3 CVE-2026-18590 A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin … No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-18587 A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a m… No fix yet Fix from $1,9502026-08-03 HIGH 8.4 CVE-2026-67323 GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing comm… No fix yet Fix from $1,9502026-08-01 CRITICAL 9.8 CVE-2026-38708 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… Mitigation only Fix from $2,3002026-07-31 HIGH 7.2 CVE-2026-38710 TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability a… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-38713 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-38711 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-43830 Full details and mitigation steps are currently restricted and will be published at a later date. No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-38709 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-35847 An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-7849 Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration whic… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.9 CVE-2026-54680 Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer Fluen… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2024-58354 cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow p… No fix yet Fix from $2,3002026-07-23