Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.3
CVE-2026-10219

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge…

Patch available
Fix from $1,950 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10214

A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools…

Patch available
Fix from $1,950 2026-06-01
Intellij Idea HIGH 7.8
CVE-2026-49366

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Fix: 2026.1.1+
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.0
CVE-2026-45630

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTra…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45633

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /dock…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified MEDIUM 6.3
CVE-2026-45626

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeNa…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45629

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment We…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 8.8
CVE-2026-45662

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/ser…

Mitigation only
Fix from $1,950 2026-05-29
Avideo HIGH 8.8
CVE-2026-45578

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branc…

Fix: after 29.0
Fix from $1,950 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41276

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41277

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware HIGH 7.2
CVE-2025-41279

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr…

Fix: after 7.9.1.0_r2502171040
Fix from $1,950 2026-05-29
Wf 500 Firmware HIGH 7.8
CVE-2025-41281

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-…

Fix: after 7.9.1.0_r2502171040
Fix from $1,950 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41269

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41270

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41272

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41274

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41275

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware HIGH 7.2
CVE-2025-41266

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr…

Fix: after 7.9.1.0_r2502171040
Fix from $1,950 2026-05-29
Wf 500 Firmware HIGH 7.2
CVE-2025-41267

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr…

Fix: after 7.9.1.0_r2502171040
Fix from $1,950 2026-05-29
Wf 500 Firmware HIGH 7.2
CVE-2025-41265

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr…

Fix: after 7.9.1.0_r2502171040
Fix from $1,950 2026-05-29
Scadabr CRITICAL 9.9
CVE-2026-9645

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabli…

Mitigation only
Fix from $2,300 2026-05-28
Zed HIGH 8.6
CVE-2026-44465

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the c…

Fix: 0.227.1+
Fix from $1,950 2026-05-28
Zed HIGH 8.6
CVE-2026-44466

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execut…

Fix: 0.229.0+
Fix from $1,950 2026-05-28
Zed HIGH 7.8
CVE-2026-44463

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allow…

Fix: 0.229.0+
Fix from $1,950 2026-05-28
Zed HIGH 8.6
CVE-2026-44461

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment v…

Fix: 0.227.1+
Fix from $1,950 2026-05-28
Openshift Container Platform CRITICAL 9.8
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …

Fix: 4.21.0+
Fix from $2,300 2026-05-28
Unclassified HIGH 7.0
CVE-2026-44604

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a s…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.8
CVE-2026-45322

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0…

Mitigation only
Fix from $1,950 2026-05-27