Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Netvault Backup HIGH 8.8
CVE-2026-9787

Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Cacti CRITICAL 9.8
CVE-2026-40079

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sani…

Fix: 1.2.31+
Fix from $2,300 2026-06-25
Insightconnect Sqlmap HIGH 8.8
CVE-2026-8659

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi…

Fix: 2.0.1+
Fix from $1,950 2026-06-25
Cacti CRITICAL 9.8
CVE-2026-39938

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Unraid HIGH 8.8
CVE-2026-9772

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

Fix: 7.3.0+
Fix from $1,950 2026-06-24
Unraid HIGH 8.8
CVE-2026-9773

Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …

Fix: 7.3.0+
Fix from $1,950 2026-06-24
Rclone CRITICAL 9.8
CVE-2026-49980

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --…

Fix: 1.74.3+
Fix from $2,300 2026-06-24
Unclassified HIGH 7.7
CVE-2026-54699

Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injecti…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.8
CVE-2026-48731

Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-48732

Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.8
CVE-2026-48703

Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution p…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.0
CVE-2026-48719

Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i…

Patch available
Fix from $1,950 2026-06-24
Git Client MEDIUM 5.0
CVE-2026-57282

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper s…

Fix: 6.6.1+
Fix from $1,600 2026-06-24
Gemini Cli HIGH 7.8
CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Act…

Fix: 0.1.22 / 0.39.1+
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12850

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12851

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12486

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12849

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Rtk Rewrite HIGH 8.8
CVE-2026-55249

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewri…

Patch available
Fix from $1,950 2026-06-23
Deno HIGH 8.1
CVE-2026-49402

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() hel…

Fix: 2.7.10+
Fix from $1,950 2026-06-23
Unclassified HIGH 8.8
CVE-2026-35018

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated a…

Mitigation only
Fix from $1,950 2026-06-23
Imagemagick HIGH 8.1
CVE-2026-56379

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-06-23
Flowise CRITICAL 9.9
CVE-2026-56274

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validatio…

Fix: 3.1.2+
Fix from $2,300 2026-06-23
Unclassified HIGH 8.7
CVE-2026-11834

A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient vali…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12815

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation le…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12814

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_co…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified HIGH 7.4
CVE-2026-48787

gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature an…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 8.2
CVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the sh…

Patch available
Fix from $1,950 2026-06-19
Unclassified HIGH 8.6
CVE-2026-12104

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authen…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 8.6
CVE-2026-40456

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the …

Patch available
Fix from $1,950 2026-06-18