Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.8
CVE-2026-40032

UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution…

Patch available
Fix from $1,950 2026-04-08
Unclassified HIGH 7.3
CVE-2026-5802

A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation …

Mitigation only
Fix from $1,950 2026-04-08
Tophat HIGH 8.8
CVE-2026-39862

Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhos…

Fix: 2.5.1+
Fix from $1,950 2026-04-08
Archer Ax53 Firmware HIGH 8.0
CVE-2026-30815

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system c…

Fix: 1.7.1+
Fix from $1,950 2026-04-08
Archer Ax53 Firmware HIGH 8.0
CVE-2026-30818

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar…

Fix: 1.7.1+
Fix from $1,950 2026-04-08
Fleet HIGH 7.8
CVE-2026-27806

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local u…

Fix: 4.81.1+
Fix from $1,950 2026-04-08
Coolercontrold HIGH 7.2
CVE-2026-5208

Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash…

Fix: after 4.0.0
Fix from $1,950 2026-04-08
Unclassified HIGH 7.3
CVE-2026-5741

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_…

Mitigation only
Fix from $1,950 2026-04-07
Unclassified CRITICAL 9.3
CVE-2026-39382

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside th…

Patch available
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2026-4631EPSS 15%

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitizati…

Mitigation only
Fix from $2,300 2026-04-07
Emissary HIGH 7.2
CVE-2026-35581

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell commands by concatenating configu…

Fix: after 8.38.0
Fix from $1,950 2026-04-07
Filebrowser HIGH 7.2
CVE-2026-35585

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 u…

Fix: after 2.63.1
Fix from $1,950 2026-04-07
Ftldns HIGH 8.8
CVE-2026-35517

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…

Fix: after 6.5
Fix from $1,950 2026-04-07
Ftldns HIGH 8.8
CVE-2026-35518

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…

Fix: after 6.5
Fix from $1,950 2026-04-07
Ftldns HIGH 8.8
CVE-2026-35519

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…

Fix: after 6.5
Fix from $1,950 2026-04-07
Ftldns HIGH 8.8
CVE-2026-35520

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…

Fix: after 6.5
Fix from $1,950 2026-04-07
Ftldns HIGH 8.8
CVE-2026-35521

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…

Fix: after 6.5
Fix from $1,950 2026-04-07
Mantaray Nm HIGH 8.0
CVE-2025-24817

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in …

Fix: 25r1-nm+
Fix from $1,950 2026-04-07
Pyload Ng HIGH 8.8
CVE-2026-35463

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restri…

Fix: after 0.5.0b3.dev96
Fix from $1,950 2026-04-07
Tianxin Internet Behavior Management System CRITICAL 9.8
CVE-2021-4473EPSS 6%

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated…

Fix: 4.0.0.7_20210716.180815+
Fix from $2,300 2026-04-07
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5692

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The m…

Mitigation only
Fix from $1,950 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5691

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. …

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5690

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. E…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5689

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5688

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $1,950 2026-04-06
Research And Engineering Studio HIGH 8.8
CVE-2026-5707

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through …

Fix: 2026.03+
Fix from $1,950 2026-04-06
Research And Engineering Studio HIGH 8.8
CVE-2026-5709

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authent…

Fix: 2026.03+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 5.5
CVE-2026-5679

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5677

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. P…

Mitigation only
Fix from $1,950 2026-04-06