Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.7
CVE-2026-54699

Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injecti…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.8
CVE-2026-48731

Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-48732

Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.8
CVE-2026-48703

Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution p…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.0
CVE-2026-48719

Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i…

Patch available
Fix from $1,950 2026-06-24
Git Client MEDIUM 5.0
CVE-2026-57282

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper s…

Fix: 6.6.1+
Fix from $1,600 2026-06-24
Gemini Cli HIGH 7.8
CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Act…

Fix: 0.1.22 / 0.39.1+
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12850

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12851

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12486

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12849

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Rtk Rewrite HIGH 8.8
CVE-2026-55249

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewri…

Patch available
Fix from $1,950 2026-06-23
Deno HIGH 8.1
CVE-2026-49402

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() hel…

Fix: 2.7.10+
Fix from $1,950 2026-06-23
Unclassified HIGH 8.8
CVE-2026-35018

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated a…

Mitigation only
Fix from $1,950 2026-06-23
Imagemagick HIGH 8.1
CVE-2026-56379

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-06-23
Flowise CRITICAL 9.9
CVE-2026-56274

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validatio…

Fix: 3.1.2+
Fix from $2,300 2026-06-23
Unclassified HIGH 8.7
CVE-2026-11834

A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient vali…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12815

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation le…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12814

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_co…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified HIGH 7.4
CVE-2026-48787

gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature an…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 8.2
CVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the sh…

Patch available
Fix from $1,950 2026-06-19
Unclassified HIGH 8.6
CVE-2026-12104

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authen…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 8.6
CVE-2026-40456

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the …

Patch available
Fix from $1,950 2026-06-18
Unclassified HIGH 7.1
CVE-2026-48997

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destinatio…

Mitigation only
Fix from $1,950 2026-06-17
Ai Toolkit CRITICAL 9.1
CVE-2026-20266

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splun…

Fix: 5.7.4+
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.6
CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed…

Patch available
Fix from $2,300 2026-06-17
Unclassified MEDIUM 6.0
CVE-2026-55748

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NO…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 7.2
CVE-2026-53876

RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the roo…

Mitigation only
Fix from $1,950 2026-06-17
Tl Wr940n Firmware HIGH 7.2
CVE-2026-11409

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of us…

Fix: 260528+
Fix from $1,950 2026-06-17
Tl Wr940n Firmware HIGH 7.2
CVE-2026-11410

An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper saniti…

Fix: 260528+
Fix from $1,950 2026-06-17