Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2026-19628

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.2
CVE-2026-19771

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73667

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates u…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73660

FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.6
CVE-2026-73662

FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg1…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.9
CVE-2026-73570

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-53790

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying m…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73623

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary co…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73625

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling gi…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73483

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-17431

PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _styl…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-49481

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d…

No fix yet
Fix from $5,750 2026-08-12
I Access Client Solutions HIGH 7.8
CVE-2026-16695

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci…

No fix yet
Fix from $4,900 2026-08-12
Informix Dynamic Server HIGH 7.3
CVE-2026-13476

IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.3
CVE-2026-73412

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly c…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.2
CVE-2026-73414

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63298

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje…

No fix yet
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-17417

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-17642

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem…

No fix yet
Fix from $4,900 2026-08-12
Security Verify Access HIGH 7.2
CVE-2026-12005

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.3
CVE-2026-18235

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input val…

Fix: after 7.6
Fix from $4,900 2026-08-12
I MEDIUM 6.3
CVE-2026-17420

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el…

Fix: after 7.6
Fix from $4,000 2026-08-12
I MEDIUM 6.5
CVE-2026-17248

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme…

Fix: after 7.6
Fix from $4,000 2026-08-12
Db2 Mirror For I CRITICAL 9.8
CVE-2026-16956

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-16856

IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-16906

IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-48553

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thr…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-48554

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macr…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-18683

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user…

No fix yet
Fix from $4,900 2026-08-12