Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2026-58455

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell comm…

Patch available
Fix from $2,300 2026-07-02
Unclassified CRITICAL 10.0
CVE-2026-56004

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _…

Patch available
Fix from $2,300 2026-07-02
Unclassified HIGH 7.5
CVE-2026-58652

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL i…

Patch available
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-58457

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified HIGH 7.3
CVE-2026-13760

OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who co…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-58452

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attacker…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34116

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php job…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34117

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34109

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/sp…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php …

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34111

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"php…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34112

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34113

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jo…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34114

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34115

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34107

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified HIGH 7.2
CVE-2026-50043

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnera…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 10.0
CVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default a…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 10.0
CVE-2026-56415

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A re…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-56700

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified MEDIUM 6.6
CVE-2026-27955

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the executeInDocker() he…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 8.8
CVE-2026-27957

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.8
CVE-2026-56137

RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.2
CVE-2026-56808

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.8
CVE-2026-34594

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-34597

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-57999

luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execu…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-58000

luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_me…

Patch available
Fix from $1,950 2026-06-29