Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Miniclaw HIGH 8.8
CVE-2026-8112

A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the f…

Fix: after 2026-04-29
Fix from $1,950 2026-05-07
Gitpython HIGH 8.8
CVE-2026-42215

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git op…

Fix: 3.1.47+
Fix from $1,950 2026-05-07
Unclassified HIGH 8.8
CVE-2025-63705

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.

Mitigation only
Fix from $1,950 2026-05-07
Virtual Storage One Block CRITICAL 9.8
CVE-2025-9661

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified HIGH 8.8
CVE-2026-31195

OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firm…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 8.8
CVE-2026-31196

OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router wit…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified CRITICAL 9.1
CVE-2026-36356EPSS 14%

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via …

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-7823

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7785

A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. T…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-41923

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthen…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41924

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unaut…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41925

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function th…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41926

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request …

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41922

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthen…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.8
CVE-2026-42076

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2025-13605

3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands …

Mitigation only
Fix from $2,300 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7730

A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the compone…

Mitigation only
Fix from $1,600 2026-05-04
Gv Lpc2011 Firmware HIGH 8.8
CVE-2026-42364

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configu…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7698

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of t…

Mitigation only
Fix from $1,950 2026-05-03
Unclassified MEDIUM 6.3
CVE-2026-7653

A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/in…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7642

A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the co…

Mitigation only
Fix from $1,600 2026-05-02
Tew 821dap Firmware HIGH 8.8
CVE-2026-7609

A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the …

No fix yet
Fix from $1,950 2026-05-02
Tew 821dap Firmware HIGH 8.0
CVE-2026-7608EPSS 5%

A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in…

No fix yet
Fix from $1,950 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7600

A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of t…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified HIGH 7.3
CVE-2026-7593

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of t…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7590

A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown …

Mitigation only
Fix from $1,950 2026-05-01
Ironic Python Agent HIGH 7.5
CVE-2026-43003

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within …

Fix: after 11.5.0
Fix from $1,950 2026-05-01
Cli CRITICAL 9.8
CVE-2026-42994

Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkma…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-7538

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2026-05-01
Openharness HIGH 8.8
CVE-2026-7551

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to…

Fix: 2026-04-27+
Fix from $1,950 2026-04-30