Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Ng Firewall MEDIUM 6.0
CVE-2026-25622EPSS 10%

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On …

Fix: 17.4.1+
Fix from $1,600 2026-06-05
Ng Firewall MEDIUM 6.0
CVE-2026-25623EPSS 6%

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generati…

Fix: 17.4.1+
Fix from $1,600 2026-06-05
Unclassified HIGH 7.7
CVE-2026-46394

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified CRITICAL 9.4
CVE-2026-46399

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file ove…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified HIGH 8.8
CVE-2026-49492

Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken …

Mitigation only
Fix from $1,950 2026-06-05
Termix CRITICAL 9.0
CVE-2026-45750

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix CRITICAL 9.8
CVE-2026-45748

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix CRITICAL 9.9
CVE-2026-45744

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Unclassified MEDIUM 6.3
CVE-2026-11341

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipu…

Mitigation only
Fix from $1,600 2026-06-05
Digital Experience HIGH 8.8
CVE-2026-21837

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary o…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 7.2
CVE-2026-10872

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. P…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.2
CVE-2026-10873

A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Exec…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.2
CVE-2026-10871

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the compo…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.2
CVE-2026-10870

A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulati…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 8.2
CVE-2025-69755

An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a …

Mitigation only
Fix from $1,950 2026-06-04
Node Version Manager HIGH 7.5
CVE-2026-10796

nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands …

Fix: 0.40.5+
Fix from $1,950 2026-06-04
Unclassified CRITICAL 9.8
CVE-2025-67447

The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does n…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.6
CVE-2026-35906

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2026-06-04
Unclassified HIGH 8.7
CVE-2026-45431

This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web manageme…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.2
CVE-2026-3820

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware MEDIUM 6.8
CVE-2026-50206

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware HIGH 8.8
CVE-2026-49190

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installa…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 6.7
CVE-2026-10805

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malform…

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49185

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Mitigation only
Fix from $2,300 2026-06-04
Unclassified HIGH 8.2
CVE-2026-41010

ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name retu…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 8.2
CVE-2026-41011

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['nam…

No fix yet
Fix from $1,950 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-36576

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arb…

Mitigation only
Fix from $2,300 2026-06-03
Sharepoint Server HIGH 8.0
CVE-2026-47294

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attack…

Fix: 16.0.19725.20280+
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10279

A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts …

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10273

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webho…

Patch available
Fix from $1,950 2026-06-01