Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.9
CVE-2026-73294

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controll…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73263

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp au…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.8
CVE-2026-11325

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execu…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.6
CVE-2026-5917

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.8
CVE-2026-14863

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-73224

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.7
CVE-2026-73081

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a…

No fix yet
Fix from $4,900 2026-08-11
Visual Studio Code HIGH 7.8
CVE-2026-70335

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unautho…

Fix: 1.132.1+
Fix from $4,900 2026-08-11
Visual Studio Code HIGH 8.8
CVE-2026-69320

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to e…

Fix: 1.132.1+
Fix from $4,900 2026-08-11
Coldfusion HIGH 7.7
CVE-2026-48385

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…

No fix yet
Fix from $4,900 2026-08-11
Coldfusion CRITICAL 10.0
CVE-2026-48362

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.4
CVE-2026-73077

Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.v…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.4
CVE-2026-67180

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evide…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.7
CVE-2026-72767

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users w…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.9
CVE-2026-72603

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by inje…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72556

A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission ch…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72551

A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exp…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.5
CVE-2026-58236

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal cod…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.6
CVE-2025-30241

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sy…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-72904

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in …

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.7
CVE-2026-72884

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts onl…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72901

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbi…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72902

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands o…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72877

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell com…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72878

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by d…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.4
CVE-2026-72879

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/clust…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72880

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/cer…

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 6.4
CVE-2026-72881

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72882

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for …

No fix yet
Fix from $5,750 2026-08-10