Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Dns 320 Firmware HIGH 7.2
CVE-2026-8271

A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp…

No fix yet
Fix from $1,950 2026-05-11
Dns 320 Firmware HIGH 7.2
CVE-2026-8272EPSS 6%

A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/web…

No fix yet
Fix from $1,950 2026-05-11
Dns 320 Firmware HIGH 7.2
CVE-2026-8273

A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the fi…

No fix yet
Fix from $1,950 2026-05-11
Ac6 Firmware HIGH 7.2
CVE-2026-8265

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFi…

No fix yet
Fix from $1,950 2026-05-11
Ac6 Firmware HIGH 8.8
CVE-2026-8264

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan…

No fix yet
Fix from $1,950 2026-05-11
Ac10u Firmware CRITICAL 9.8
CVE-2026-8263

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtr…

Mitigation only
Fix from $2,300 2026-05-11
Ac6 Firmware HIGH 7.2
CVE-2026-8259

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component …

No fix yet
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.5
CVE-2026-8235

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the…

Patch available
Fix from $1,600 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8227

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation c…

No fix yet
Fix from $1,950 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8228

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipu…

No fix yet
Fix from $1,950 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8229

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing …

No fix yet
Fix from $1,950 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8230

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipula…

No fix yet
Fix from $1,950 2026-05-10
Unclassified MEDIUM 6.3
CVE-2026-8217

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the c…

Mitigation only
Fix from $1,600 2026-05-10
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8192

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Per…

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8191EPSS 5%

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulatio…

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8190EPSS 5%

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipu…

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8189

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. …

No fix yet
Fix from $1,950 2026-05-09
Wl Nu516u1 Firmware HIGH 8.8
CVE-2026-8188EPSS 5%

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The mani…

No fix yet
Fix from $1,950 2026-05-09
Unclassified HIGH 7.2
CVE-2026-3828

Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input …

Mitigation only
Fix from $1,950 2026-05-09
Unclassified CRITICAL 9.9
CVE-2026-42454

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker cont…

Mitigation only
Fix from $2,300 2026-05-08
Vim MEDIUM 5.3
CVE-2026-44656

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line …

Fix: 9.2.0435+
Fix from $1,600 2026-05-08
Praisonai CRITICAL 9.8
CVE-2026-41497

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg…

Fix: 4.6.9+
Fix from $2,300 2026-05-08
Unclassified HIGH 8.1
CVE-2022-50994

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthentica…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-8153

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft co…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified HIGH 7.3
CVE-2025-67888

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "ap…

Mitigation only
Fix from $1,950 2026-05-08
Librenms CRITICAL 9.1
CVE-2024-51092EPSS 7%

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…

Fix: 24.10.0+
Fix from $2,300 2026-05-08
Broadcast Message Center MEDIUM 6.5
CVE-2022-45899

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacter…

Fix: 13.1+
Fix from $1,600 2026-05-08
Electerm HIGH 7.8
CVE-2026-43943

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerabilit…

Fix: 3.7.9+
Fix from $1,950 2026-05-08
Openshift Ai HIGH 8.8
CVE-2026-42271 KEVEPSS 83%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

Fix: 1.83.7 / 2.25.8+
Fix from $1,950 2026-05-08
Openlearnx CRITICAL 10.0
CVE-2026-41900

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was…

Patch available
Fix from $2,300 2026-05-08