Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2026-8500

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpass…

Mitigation only
Fix from $2,300 2026-05-13
Opnsense CRITICAL 9.1
CVE-2026-44194EPSS 6%

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens…

Fix: 26.1.8+
Fix from $2,300 2026-05-13
Pan Os HIGH 7.2
CVE-2026-0261

Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-05-13
Unclassified HIGH 8.8
CVE-2026-6281

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local networ…

Mitigation only
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-42924

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Protobufjs Cli HIGH 7.8
CVE-2026-42290

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input…

Fix: 1.2.1 / 2.0.2+
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-34176

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Unclassified CRITICAL 9.8
CVE-2026-42062

ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arb…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified HIGH 7.2
CVE-2026-35506

ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a craft…

Mitigation only
Fix from $1,950 2026-05-13
Filemaker Cloud HIGH 7.2
CVE-2026-43685

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system com…

Fix: 2.22.0.5+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-44258

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and hom…

Mitigation only
Fix from $2,300 2026-05-12
Arubaos HIGH 7.2
CVE-2026-23820

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execu…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-23821

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system …

Fix: 8.10.0.0 / 8.12.0.7+
Fix from $1,950 2026-05-12
Visual Studio Code HIGH 8.8
CVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.119.1+
Fix from $1,950 2026-05-12
Fortiap MEDIUM 6.7
CVE-2025-53870

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, …

Fix: 7.2.6 / 7.4.5+
Fix from $1,600 2026-05-12
Fortiap MEDIUM 6.7
CVE-2025-53680

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiA…

Fix: 7.0.6 / 7.4.5+
Fix from $1,600 2026-05-12
Unclassified HIGH 8.4
CVE-2026-43991

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 8.4
CVE-2026-43990

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command …

Patch available
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31226

The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) i…

Mitigation only
Fix from $2,300 2026-05-12
Virtual Traffic Manager HIGH 7.2
CVE-2026-8051

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve …

Fix: after 22.8
Fix from $1,950 2026-05-12
Insightiq HIGH 8.2
CVE-2026-35071

Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command I…

Fix: 6.3.0+
Fix from $1,950 2026-05-12
Ruggedcom Rox Mx5000 Firmware HIGH 7.5
CVE-2025-40947

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX …

Fix: 2.17.1+
Fix from $1,950 2026-05-12
Ruggedcom Rox Mx5000 Firmware CRITICAL 9.1
CVE-2025-40949

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX …

Fix: 2.17.1+
Fix from $2,300 2026-05-12
Wre6505 Firmware HIGH 8.8
CVE-2026-7256

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.8
CVE-2026-45391

A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary command…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.8
CVE-2026-45393

A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.1
CVE-2026-30635

Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in t…

Mitigation only
Fix from $1,950 2026-05-11
Pgadmin 4 HIGH 8.8
CVE-2026-7816

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy…

Fix: 9.15+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.5
CVE-2026-31246

GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the Executor.run()…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 8.0
CVE-2026-4802

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized…

Mitigation only
Fix from $1,950 2026-05-11