Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
MEDIUM 6.3 CVE-2026-12815 A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation le… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.3 CVE-2026-12814 A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_co… Mitigation only Fix from $1,6002026-06-21 MEDIUM 6.3 CVE-2026-12810 A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the comp… Mitigation only Fix from $1,6002026-06-21 MEDIUM 6.3 CVE-2026-12809 A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the c… Mitigation only Fix from $1,6002026-06-21 MEDIUM 6.3 CVE-2026-12807 A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Hand… Mitigation only Fix from $1,6002026-06-21 MEDIUM 6.3 CVE-2026-12808 A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Reque… Mitigation only Fix from $1,6002026-06-21 HIGH 7.5 CVE-2026-42895 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t… 365 Copilot Mitigation only Fix from $1,9502026-06-19 HIGH 8.8 CVE-2026-12045 Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute … Pgadmin 4 9.16+ Fix from $1,9502026-06-19 CRITICAL 9.8 CVE-2026-38714 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-38715 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-38716 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-38717 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 HIGH 8.8 CVE-2024-24909 Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authen… Mitigation only Fix from $1,9502026-06-16 HIGH 7.8 CVE-2025-56814 A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metachar… Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.5 CVE-2026-12223 A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file … Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.3 CVE-2026-12219 A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnos… Mitigation only Fix from $1,6002026-06-15 HIGH 7.2 CVE-2026-12197 A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of… Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-12187 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /… Mitigation only Fix from $1,9502026-06-14 HIGH 8.8 CVE-2026-12186 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor o… Mitigation only Fix from $1,9502026-06-14 HIGH 8.8 CVE-2026-53822 OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers … Openclaw 2026.5.18+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-42850 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error.… Kitty 0.47.0+ Fix from $1,9502026-06-12 HIGH 7.8 CVE-2026-46529 Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in… Mitigation only Fix from $1,9502026-06-10 CRITICAL 9.9 CVE-2026-45558 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi… Mitigation only Fix from $2,3002026-06-10 HIGH 8.8 CVE-2026-11572 Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user inpu… Patch available Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-11556 A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the co… Mitigation only Fix from $1,9502026-06-08 MEDIUM 5.3 CVE-2026-11487 A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component V… Patch available Fix from $1,6002026-06-08 MEDIUM 5.0 CVE-2026-11455 A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/u… Mitigation only Fix from $1,6002026-06-07 HIGH 7.3 CVE-2026-11451 A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. … Mitigation only Fix from $1,9502026-06-07 HIGH 7.3 CVE-2026-11452 A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_… Mitigation only Fix from $1,9502026-06-07 MEDIUM 6.3 CVE-2026-11449 A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of … Mitigation only Fix from $1,6002026-06-07