Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.1
CVE-2026-22313

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulner…

Mitigation only
Fix from $2,300 2026-06-16
Unclassified HIGH 8.8
CVE-2026-44932

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DH…

Mitigation only
Fix from $1,950 2026-06-16
Unclassified HIGH 7.5
CVE-2026-12398

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized …

Mitigation only
Fix from $1,950 2026-06-16
Unclassified HIGH 8.8
CVE-2026-5416

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vuln…

Mitigation only
Fix from $1,950 2026-06-16
Remote Desktop Manager HIGH 8.8
CVE-2026-12161

Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to ex…

Fix: 2026.2.8.0+
Fix from $1,950 2026-06-16
Unclassified HIGH 7.8
CVE-2026-48723

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable t…

Patch available
Fix from $1,950 2026-06-15
Unclassified HIGH 8.1
CVE-2026-50874

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbit…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38060

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38061

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38062

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38063

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38064

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38065

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

Mitigation only
Fix from $2,300 2026-06-15
Core Privileged Access Manager Server CRITICAL 9.8
CVE-2026-9862

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w…

Fix: 8.1.0.23 / 9.0.0.5+
Fix from $2,300 2026-06-15
Core Privileged Access Manager Server HIGH 8.8
CVE-2026-9863

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations.…

Fix: 8.1.0.23 / 9.0.0.5+
Fix from $1,950 2026-06-15
Unclassified HIGH 8.6
CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_fi…

Patch available
Fix from $1,950 2026-06-14
Unclassified CRITICAL 9.8
CVE-2026-11526

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Ima…

Patch available
Fix from $2,300 2026-06-14
Unclassified CRITICAL 9.9
CVE-2026-46716

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified MEDIUM 6.5
CVE-2026-42853

ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a com…

Mitigation only
Fix from $1,600 2026-06-12
MariaDB HIGH 7.2
CVE-2026-48163

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11…

Fix: 10.6.27 / 10.11.18+
Fix from $1,950 2026-06-12
MariaDB HIGH 7.2
CVE-2026-48165

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11…

Fix: 10.6.27 / 10.11.18+
Fix from $1,950 2026-06-12
MariaDB HIGH 8.0
CVE-2026-44168

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11…

Fix: 10.6.26 / 10.11.17+
Fix from $1,950 2026-06-12
MariaDB CRITICAL 9.8
CVE-2026-44170

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11…

Fix: 10.6.26 / 10.11.17+
Fix from $2,300 2026-06-12
Unclassified HIGH 7.2
CVE-2026-11845

The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote atta…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-42846

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user…

Mitigation only
Fix from $2,300 2026-06-11
Idira Privileged Session Manager For Ssh HIGH 8.8
CVE-2026-45172

Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authen…

Fix: 14.0.6 / 14.2.5+
Fix from $1,950 2026-06-11
Unclassified HIGH 7.3
CVE-2026-48547

KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting…

Patch available
Fix from $1,950 2026-06-11
MariaDB CRITICAL 9.8
CVE-2026-49261

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8…

Fix: 10.6.27 / 10.11.18+
Fix from $2,300 2026-06-11
Imagemagick MEDIUM 5.5
CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect…

Fix: 6.9.13-48 / 7.1.2-24+
Fix from $1,600 2026-06-10
Unclassified HIGH 7.7
CVE-2026-42563

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `Proc…

Patch available
Fix from $1,950 2026-06-10