Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified MEDIUM 5.3
CVE-2026-15669

A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go …

Mitigation only
Fix from $1,600 2026-07-14
Flamingo CRITICAL 9.8
CVE-2026-60121

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers…

Fix: after 4.12.2
Fix from $2,300 2026-07-13
Flamingo CRITICAL 9.8
CVE-2026-61498

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote una…

Fix: after 4.12.2
Fix from $2,300 2026-07-13
Unclassified HIGH 8.6
CVE-2026-22100

The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be execute…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15546

A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. …

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15547

A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15513

A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Perform…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-15511

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of th…

Mitigation only
Fix from $2,300 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15495

A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java…

No fix yet
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15496

A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/mai…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15487

A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmwa…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15486

A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component F…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15485

A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the compo…

Mitigation only
Fix from $1,600 2026-07-12
Control Panel HIGH 8.8
CVE-2025-30007

HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary…

Fix: 1.9.5+
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-54149

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP r…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-61434

PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted com…

Mitigation only
Fix from $1,950 2026-07-10
Powerflex Manager CRITICAL 9.1
CVE-2026-56688

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inject…

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.0
CVE-2026-41880

R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 8.7
CVE-2026-41876

R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file…

Mitigation only
Fix from $1,950 2026-07-10
Pan Os HIGH 7.2
CVE-2026-0286

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute ar…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-07-09
Unclassified HIGH 7.2
CVE-2026-59721

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts…

Patch available
Fix from $1,950 2026-07-09
Unclassified CRITICAL 10.0
CVE-2026-59726

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp…

Patch available
Fix from $2,300 2026-07-09
Unclassified HIGH 8.8
CVE-2026-59734

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/Appli…

Patch available
Fix from $1,950 2026-07-09
Discourse HIGH 8.1
CVE-2026-55420

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, proce…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,950 2026-07-09
Gpsd CRITICAL 9.6
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS…

Fix: after 3.27.5
Fix from $2,300 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-15193

A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/mai…

Patch available
Fix from $1,600 2026-07-09
Bosh Cli HIGH 7.8
CVE-2026-41857

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh …

Fix: 7.10.5+
Fix from $1,950 2026-07-09
Unclassified HIGH 8.5
CVE-2026-55849

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --work…

Patch available
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-60102

Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCom…

Patch available
Fix from $1,950 2026-07-08
Rv130 Firmware HIGH 7.2
CVE-2026-24700

An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W …

No fix yet
Fix from $1,950 2026-07-08