Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2026-7125

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cs…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7123

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the compon…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7124

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7122

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the …

Mitigation only
Fix from $2,300 2026-04-27
Hg3 Firmware HIGH 8.8
CVE-2026-7119

A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of t…

No fix yet
Fix from $1,950 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7121

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the compone…

Mitigation only
Fix from $2,300 2026-04-27
Hg3 Firmware HIGH 8.8
CVE-2026-7096

A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formg…

No fix yet
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7066

A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function ex…

Mitigation only
Fix from $1,950 2026-04-27
Logontracer HIGH 8.8
CVE-2026-33277

An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.

Fix: 2.0.0+
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7062

A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of t…

Mitigation only
Fix from $1,950 2026-04-26
Unclassified HIGH 7.3
CVE-2026-7064

A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/brows…

Mitigation only
Fix from $1,950 2026-04-26
Unclassified HIGH 7.3
CVE-2026-7061

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/serv…

Mitigation only
Fix from $1,950 2026-04-26
Unclassified CRITICAL 9.8
CVE-2026-7037

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstec…

Mitigation only
Fix from $2,300 2026-04-26
Mr9600 Firmware HIGH 7.2
CVE-2026-6992EPSS 6%

A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_c…

No fix yet
Fix from $1,950 2026-04-25
Unclassified HIGH 8.8
CVE-2026-41421

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Ele…

Mitigation only
Fix from $1,950 2026-04-24
Vim MEDIUM 6.6
CVE-2026-41411

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resol…

Fix: 9.2.0357+
Fix from $1,600 2026-04-24
Roxy Wi HIGH 8.8
CVE-2026-33208

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-co…

Fix: 8.2.6.4+
Fix from $1,950 2026-04-24
Radare2 Mcp Server HIGH 8.8
CVE-2026-6942

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by by…

Fix: 1.7.0+
Fix from $1,950 2026-04-23
Elfinder CRITICAL 9.8
CVE-2026-41247

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner…

Fix: 2.1.67+
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31178

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par…

Mitigation only
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31181

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p…

Mitigation only
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31177

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par…

Mitigation only
Fix from $2,300 2026-04-23
Paperclipai HIGH 8.8
CVE-2026-41208

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416…

Fix: 2026.416.0+
Fix from $1,950 2026-04-23
Total Storage Service Console CRITICAL 9.8
CVE-2026-5935

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma…

Mitigation only
Fix from $2,300 2026-04-23
Rclone CRITICAL 9.8
CVE-2026-41179EPSS 9%

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to…

Fix: 1.73.5+
Fix from $2,300 2026-04-23
Radare2 HIGH 7.8
CVE-2026-40517

radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitra…

Fix: 6.1.4+
Fix from $1,950 2026-04-22
Avideo CRITICAL 9.3
CVE-2026-41064

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f…

Fix: after 29.0
Fix from $2,300 2026-04-22
Flowise CRITICAL 9.9
CVE-2026-40933EPSS 13%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…

Fix: 3.1.0+
Fix from $2,300 2026-04-21
Bamboo HIGH 8.8
CVE-2026-21571

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1…

Fix: 9.6.25 / 10.2.18+
Fix from $1,950 2026-04-21
Dolibarr Erp\/crm HIGH 8.8
CVE-2026-31019

In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions rela…

Fix: after 22.0.4
Fix from $1,950 2026-04-21