Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 8.8
CVE-2026-52876

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler i…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-55426

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.6
CVE-2026-53455

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git c…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-71551

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75094

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-67965

An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-71858

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC valid…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-71472

A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.1
CVE-2026-68519

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-62982

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-68518

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.8
CVE-2026-75056

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.7
CVE-2026-71567

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.3
CVE-2026-56685

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.8
CVE-2026-56686

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.8
CVE-2026-59910

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-74997

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via craf…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.2
CVE-2026-74801

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19982

A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-mana…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.3
CVE-2026-19983

A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown proce…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19981

A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-19978

A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_proc…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.8
CVE-2026-73680

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the asset…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.9
CVE-2026-17186

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.5
CVE-2026-17179

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 10.0
CVE-2026-19188

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19679

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contr…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.9
CVE-2026-19681

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.9
CVE-2026-19682

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19635

A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve ar…

No fix yet
Fix from $4,900 2026-08-14