Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Pan Os HIGH 7.2
CVE-2026-0273

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-6893

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Hos…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-46643

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 8.5
CVE-2026-9151

An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerabili…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.9
CVE-2026-46618

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,600 2026-06-10
Unclassified HIGH 7.3
CVE-2026-11417

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who contro…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 8.8
CVE-2026-45564

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45556

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>…

Mitigation only
Fix from $2,300 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45558

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi…

Mitigation only
Fix from $2,300 2026-06-10
Qts HIGH 7.2
CVE-2026-24719

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3492+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2026-22893

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2025-66273

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Qts HIGH 7.2
CVE-2025-66279

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc…

Fix: 5.2.9.3410+
Fix from $1,950 2026-06-10
Unclassified HIGH 8.8
CVE-2026-49959

Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands…

Patch available
Fix from $1,950 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-38615

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

Mitigation only
Fix from $2,300 2026-06-09
Fortisandbox CRITICAL 9.8
CVE-2026-25089 KEVEPSS 74%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-06-09
Standalone Sentry CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Unclassified HIGH 7.2
CVE-2026-10727EPSS 14%

An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execut…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 8.7
CVE-2026-9279

Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, …

Mitigation only
Fix from $1,950 2026-06-09
Sinec Ins HIGH 8.8
CVE-2026-46746

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /ap…

Fix: after 1.0
Fix from $1,950 2026-06-09
Unclassified HIGH 8.8
CVE-2026-11572

Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user inpu…

Patch available
Fix from $1,950 2026-06-09
Unclassified HIGH 7.5
CVE-2026-40519

Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS comm…

Patch available
Fix from $1,950 2026-06-08
Devolutions Server MEDIUM 6.5
CVE-2026-10544

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated us…

Fix: 2026.1.21.0+
Fix from $1,600 2026-06-08
Unclassified HIGH 8.5
CVE-2026-8913

A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled i…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified HIGH 8.8
CVE-2026-11556

A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the co…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified HIGH 8.8
CVE-2026-25855

OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by upl…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified MEDIUM 6.3
CVE-2026-11408

A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of t…

Patch available
Fix from $1,600 2026-06-06
Open Xdmod CRITICAL 9.8
CVE-2026-45777

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remot…

Fix: 11.0.3+
Fix from $2,300 2026-06-05
Ng Firewall MEDIUM 6.0
CVE-2026-25620EPSS 10%

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Ne…

Mitigation only
Fix from $1,600 2026-06-05
Ng Firewall MEDIUM 6.0
CVE-2026-25621

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure i…

Mitigation only
Fix from $1,600 2026-06-05