Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified MEDIUM 6.3
CVE-2026-13581

A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup o…

Mitigation only
Fix from $1,600 2026-06-29
Claude Code HIGH 8.8
CVE-2026-55607

Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and nav…

Fix: 2.1.163+
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13561

A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the c…

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13560

A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept …

Mitigation only
Fix from $1,600 2026-06-29
Dcs 935l Firmware HIGH 8.8
CVE-2026-13545

A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Paramet…

No fix yet
Fix from $1,950 2026-06-29
Unclassified HIGH 7.2
CVE-2026-55975

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate gener…

Mitigation only
Fix from $1,950 2026-06-26
Kestra CRITICAL 10.0
CVE-2026-49869

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Notepad\+\+ HIGH 7.8
CVE-2026-48778

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by …

Fix: 8.9.6.1+
Fix from $1,950 2026-06-26
Notepad\+\+ HIGH 7.8
CVE-2026-48800

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xm…

Fix: 8.9.6.1+
Fix from $1,950 2026-06-26
Unclassified HIGH 8.8
CVE-2026-32833

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.6
CVE-2026-55441

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.3
CVE-2026-55448

mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local projec…

Mitigation only
Fix from $1,600 2026-06-26
Dokku CRITICAL 9.9
CVE-2026-54636

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku us…

Fix: 0.38.7+
Fix from $2,300 2026-06-26
Dokku CRITICAL 9.0
CVE-2026-45408

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authentic…

Fix: 0.38.2+
Fix from $2,300 2026-06-26
Unclassified HIGH 8.0
CVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an…

Mitigation only
Fix from $1,950 2026-06-26
Flowise CRITICAL 9.8
CVE-2025-71336

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feat…

Fix: 3.0.6+
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.3
CVE-2026-54088

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified HIGH 7.8
CVE-2026-46606

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/…

Mitigation only
Fix from $1,950 2026-06-25
Pnpm HIGH 8.8
CVE-2026-55697

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. …

Fix: 10.34.2 / 11.5.3+
Fix from $1,950 2026-06-25
Powerlogic P7 Firmware HIGH 7.2
CVE-2026-9717

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution…

Fix: 02.004.001.000+
Fix from $1,950 2026-06-25
Vim HIGH 7.8
CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the ne…

Fix: 9.2.0663+
Fix from $1,950 2026-06-25
Display And Peripheral Manager HIGH 7.8
CVE-2026-46735

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command (…

Fix: 2.3.0+
Fix from $1,950 2026-06-25
Insightconnect Tcpdump HIGH 8.8
CVE-2026-8658

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands v…

Fix: 2.0.0+
Fix from $1,950 2026-06-25
Insightconnect Ping CRITICAL 9.8
CVE-2026-8660

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS c…

Fix: 1.0.4+
Fix from $2,300 2026-06-25
Insightconnect Finger HIGH 8.8
CVE-2026-8664

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi…

Fix: 1.0.3+
Fix from $1,950 2026-06-25
Insightconnect Translate CRITICAL 9.8
CVE-2026-8665

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary O…

Fix: 2.0.3+
Fix from $2,300 2026-06-25
Insightconnect Traceroute CRITICAL 9.8
CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ar…

Fix: 1.0.3+
Fix from $2,300 2026-06-25
Insightconnect Awk CRITICAL 9.8
CVE-2026-8592

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbit…

Fix: 1.2.2+
Fix from $2,300 2026-06-25
Sed HIGH 8.8
CVE-2026-9155

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…

Mitigation only
Fix from $1,950 2026-06-25
Insightconnect Rpm HIGH 8.8
CVE-2026-8663

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…

Fix: 1.0.2+
Fix from $1,950 2026-06-25