Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.3 CVE-2026-15546 A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. … Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15547 A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15513 A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Perform… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.8 CVE-2026-15511 A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of th… Mitigation only Fix from $2,3002026-07-12 MEDIUM 6.3 CVE-2026-15495 A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java… No fix yet Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15496 A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/mai… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15487 A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmwa… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15486 A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component F… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15485 A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the compo… Mitigation only Fix from $1,6002026-07-12 HIGH 8.8 CVE-2026-15481 A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of t… Mitigation only Fix from $1,9502026-07-12 HIGH 8.8 CVE-2025-6784 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortco… Mitigation only Fix from $1,9502026-07-11 HIGH 7.2 CVE-2026-59721 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts… Patch available Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-15193 A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/mai… Patch available Fix from $1,6002026-07-09 MEDIUM 6.3 CVE-2026-15033 A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the f… Mitigation only Fix from $1,6002026-07-08 HIGH 7.8 CVE-2026-15035 A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component M… Openllm Patch available Fix from $1,9502026-07-08 HIGH 7.3 CVE-2026-14802 A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js… Mitigation only Fix from $1,9502026-07-06 HIGH 8.8 CVE-2026-54402 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute… Unifi Os Server after 5.1.15 Fix from $1,9502026-07-02 HIGH 7.2 CVE-2026-9834 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all version… Mitigation only Fix from $1,9502026-07-02 MEDIUM 6.5 CVE-2026-38142 An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to e… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.3 CVE-2026-13581 A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup o… Mitigation only Fix from $1,6002026-06-29 MEDIUM 6.3 CVE-2026-13561 A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the c… Mitigation only Fix from $1,6002026-06-29 MEDIUM 6.3 CVE-2026-13560 A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept … Mitigation only Fix from $1,6002026-06-29 HIGH 8.8 CVE-2026-13545 A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Paramet… Dcs 935l Firmware No fix yet Fix from $1,9502026-06-29 MEDIUM 6.3 CVE-2026-13538 A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.c… Mitigation only Fix from $1,6002026-06-29 MEDIUM 5.3 CVE-2026-13501 A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src… Mitigation only Fix from $1,6002026-06-28 HIGH 8.7 CVE-2026-54090 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.3… Mitigation only Fix from $1,9502026-06-25 HIGH 7.3 CVE-2026-57453 Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell … Vim 9.2.0678+ Fix from $1,9502026-06-25 CRITICAL 9.9 CVE-2026-52806 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server… Patch available Fix from $2,3002026-06-24 MEDIUM 5.8 CVE-2026-47240 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands acce… Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.8 CVE-2026-47242 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called wit… Mitigation only Fix from $1,6002026-06-22