Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Api HIGH 8.8
CVE-2026-40520

FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation …

Fix: 17.0.8+
Fix from $1,950 2026-04-21
Qn I 470 Firmware HIGH 8.8
CVE-2026-41036

This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authen…

Patch available
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.8
CVE-2026-5965

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands an…

Mitigation only
Fix from $2,300 2026-04-21
Flowsint CRITICAL 9.8
CVE-2026-32311

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a u…

Patch available
Fix from $2,300 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-24506

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,950 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-26942

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command …

Fix: 2.7.9 / 8.6.1.0+
Fix from $1,950 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-26943

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,950 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-22761

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access coul…

Fix: 2.7.9 / 8.6.1.0+
Fix from $1,950 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-23774

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…

Fix: 2.7.9 / 7.13.1.50+
Fix from $1,950 2026-04-20
Threatsonar Anti Ransomware HIGH 8.8
CVE-2026-5967

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can injec…

Fix: 4.0.0+
Fix from $1,950 2026-04-20
Data Master CRITICAL 9.1
CVE-2026-6644

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…

Fix: 4.3.3.RR42 / 5.1.2.reo1+
Fix from $2,300 2026-04-20
Emissary HIGH 8.8
CVE-2026-35582

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection beca…

Fix: 8.43.0+
Fix from $1,950 2026-04-18
Radare2 HIGH 7.8
CVE-2026-40527

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malici…

Fix: 6.1.6+
Fix from $1,950 2026-04-17
Xrdp MEDIUM 6.3
CVE-2026-33145

xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsa…

Fix: 0.10.6+
Fix from $1,600 2026-04-17
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2026-23500

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT …

Fix: 23.0.0+
Fix from $2,300 2026-04-17
Unclassified HIGH 7.2
CVE-2026-6483EPSS 14%

A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. …

Mitigation only
Fix from $1,950 2026-04-17
Powerprotect Dp Series Appliance MEDIUM 6.7
CVE-2026-35072

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,600 2026-04-17
Data Domain Operating System MEDIUM 6.7
CVE-2026-35073

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…

Fix: 7.13.1.70 / 8.3.1.30+
Fix from $1,600 2026-04-17
Powerprotect Dp Series Appliance MEDIUM 6.7
CVE-2026-35074

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,600 2026-04-17
Cubecart HIGH 7.2
CVE-2026-21719

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitr…

Fix: 6.6.0+
Fix from $1,950 2026-04-17
Unclassified HIGH 8.1
CVE-2026-41113

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.

Patch available
Fix from $1,950 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-6349

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS command…

Mitigation only
Fix from $2,300 2026-04-16
Unclassified HIGH 7.4
CVE-2026-41015

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed…

Patch available
Fix from $1,950 2026-04-16
Composer HIGH 7.8
CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce…

Fix: after 2.9.5
Fix from $1,950 2026-04-15
Composer HIGH 8.8
CVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce…

Fix: after 2.9.5
Fix from $1,950 2026-04-15
Radare2 HIGH 7.8
CVE-2026-40499

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute…

Fix: after 6.1.4
Fix from $1,950 2026-04-15
Podman HIGH 7.8
CVE-2026-33414

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine b…

Fix: 5.8.2+
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 8.8
CVE-2026-35196

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/i…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Openitcockpit HIGH 8.8
CVE-2026-24893

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contai…

Fix: 5.5.2+
Fix from $1,950 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39808 KEVEPSS 91%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: after 4.4.9
Fix from $2,300 2026-04-14