Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Connect HIGH 8.8
CVE-2026-9208

Tanium addressed an unauthorized code execution vulnerability in Connect.

Fix: 5.26.191 / 5.29.237+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.8
CVE-2026-45152

uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.2
CVE-2026-44712

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the confi…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-44713

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment vari…

Mitigation only
Fix from $1,950 2026-05-27
Claude Code Cache Fix HIGH 7.8
CVE-2026-45136

claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) int…

Fix: 3.5.2+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.8
CVE-2026-44709

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP en…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-44590

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified HIGH 7.8
CVE-2026-44724

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command inj…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 10.0
CVE-2026-45087

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf…

Mitigation only
Fix from $2,300 2026-05-27
Bentoml HIGH 8.8
CVE-2026-44345

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/con…

Fix: 1.4.39+
Fix from $1,950 2026-05-27
Bentoml HIGH 8.8
CVE-2026-44346

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam…

Fix: 1.4.39+
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-36044

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-36045

picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function atte…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.2
CVE-2026-40852

A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly ch…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.1
CVE-2026-8450

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(…

Patch available
Fix from $2,300 2026-05-27
Connect HIGH 8.8
CVE-2026-9207

Tanium addressed an unauthorized code execution vulnerability in Connect.

Fix: 5.26.191 / 5.29.237+
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.1
CVE-2026-44444

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts…

Mitigation only
Fix from $2,300 2026-05-26
Connect HIGH 7.8
CVE-2026-9560

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with eleva…

Fix: 3.8.2+
Fix from $1,950 2026-05-26
Twenty CRITICAL 9.9
CVE-2026-46624

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL …

Fix: 1.16.7+
Fix from $2,300 2026-05-26
Fastnetmon HIGH 8.1
CVE-2026-48694

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_…

Fix: after 1.2.9
Fix from $1,950 2026-05-26
Fastnetmon HIGH 8.1
CVE-2026-48695

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() funct…

Fix: after 1.2.9
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9565

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/age…

Mitigation only
Fix from $1,600 2026-05-26
Vowpal Wabbit CRITICAL 9.9
CVE-2026-44723

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly i…

Fix: 2026-05-04+
Fix from $2,300 2026-05-26
Fastnetmon CRITICAL 9.8
CVE-2026-48687

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() functi…

Fix: after 1.2.9
Fix from $2,300 2026-05-26
Openshift Container Platform CRITICAL 9.0
CVE-2026-4480EPSS 14%

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print…

Fix: 4.2.1+
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.8
CVE-2026-9543

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of th…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9532EPSS 11%

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bi…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9533EPSS 11%

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi o…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9534EPSS 11%

A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Se…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9531EPSS 11%

A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the compo…

Mitigation only
Fix from $1,600 2026-05-26