Vulnerability index

Browse CVEs

3,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
HIGH 7.3 CVE-2026-11450 A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Pat… Mitigation only Fix from $1,9502026-06-07 MEDIUM 6.3 CVE-2026-11447 A security flaw has been discovered in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function iwinfo_backend of the file iwinfo.so of the component … Mitigation only Fix from $1,6002026-06-07 MEDIUM 6.3 CVE-2026-11408 A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of t… Patch available Fix from $1,6002026-06-06 MEDIUM 6.3 CVE-2026-11406 A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component Open… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.3 CVE-2026-11341 A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipu… Mitigation only Fix from $1,6002026-06-05 HIGH 8.8 CVE-2026-11339 A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The … Dwr M920 Firmware No fix yet Fix from $1,9502026-06-05 HIGH 8.8 CVE-2026-10878 A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a ma… Dwr M920 Firmware No fix yet Fix from $1,9502026-06-05 HIGH 7.5 CVE-2026-42824EPSS 8% Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… Copilot Mitigation only Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-45497 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute cod… Copilot Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10872 A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. P… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10873 A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Exec… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10871 A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the compo… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10870 A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulati… Mitigation only Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-8037 KEVEPSS 99% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com… Connection Manager For Objectscale 7.2.54.18 / 7.2.63.2+ Fix from $2,3002026-06-04 MEDIUM 6.3 CVE-2026-10550 A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.3 CVE-2026-10279 A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts … Mitigation only Fix from $1,6002026-06-01 HIGH 8.3 CVE-2024-52011 launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of th… Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10273 A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webho… Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10219 A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge… Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10214 A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools… Patch available Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10182 A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. … Mitigation only Fix from $1,6002026-05-31 MEDIUM 6.3 CVE-2026-10180 A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation … Mitigation only Fix from $1,6002026-05-31 MEDIUM 6.3 CVE-2026-10166 A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the comp… Mitigation only Fix from $1,6002026-05-31 MEDIUM 6.3 CVE-2026-10127 A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the compone… Mitigation only Fix from $1,6002026-05-30 CRITICAL 9.6 CVE-2026-45628 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template lit… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45663 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upl… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10060EPSS 5% A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulat… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10061EPSS 5% A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argum… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-49199 Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. Predator Connect W6x Firmware Mitigation only Fix from $2,3002026-05-29 HIGH 7.2 CVE-2026-49196 The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. Predator Connect W6x Firmware Mitigation only Fix from $1,9502026-05-29