Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Firewall Community HIGH 8.8
CVE-2026-34797

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi.…

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34794

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. …

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34795

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. …

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34792

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cg…

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34793

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.…

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34791

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi…

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Glances HIGH 7.8
CVE-2026-33641

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which subst…

Fix: 4.5.3+
Fix from $1,950 2026-04-02
Flowmon HIGH 8.8
CVE-2026-3692

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the repo…

Fix: 12.5.8+
Fix from $1,950 2026-04-02
Sharefile Storage Zones Controller HIGH 8.8
CVE-2026-2701EPSS 57%

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Fix: 5.12.4+
Fix from $1,950 2026-04-02
Mbconnect24 HIGH 8.8
CVE-2026-33613

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpAr…

Fix: after 2.19.4
Fix from $1,950 2026-04-02
Security Verify Access HIGH 7.3
CVE-2026-1345

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-01
Jetson Linux MEDIUM 6.8
CVE-2026-24154

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A …

Fix: 35.6.4 / 36.5+
Fix from $1,600 2026-03-31
Wenxian CRITICAL 9.8
CVE-2026-34243

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Action…

Fix: after 0.3.1
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.8
CVE-2026-30312

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…

Mitigation only
Fix from $2,300 2026-03-31
Auto Approval Module CRITICAL 9.8
CVE-2026-30314

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…

Fix: after 0.1.1
Fix from $2,300 2026-03-31
Infcode HIGH 7.8
CVE-2026-30309

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely…

Fix: after 1.3.1
Fix from $1,950 2026-03-31
Auto Approval Module CRITICAL 9.8
CVE-2026-30311

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…

Fix: after 0.1.1
Fix from $2,300 2026-03-31
Mlflow HIGH 7.8
CVE-2026-0596

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into…

No fix yet
Fix from $1,950 2026-03-31
Openclaw CRITICAL 9.8
CVE-2026-32917

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute …

Fix: 2026.3.13+
Fix from $2,300 2026-03-31
Unclassified HIGH 8.3
CVE-2025-14213

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket …

Mitigation only
Fix from $1,950 2026-03-31
Basercms CRITICAL 9.8
CVE-2026-30880

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue …

Fix: 5.2.3+
Fix from $2,300 2026-03-31
Basercms HIGH 7.2
CVE-2026-21861

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update funct…

Fix: 5.2.3+
Fix from $1,950 2026-03-31
Basercms HIGH 7.2
CVE-2026-30877

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due …

Fix: 5.2.3+
Fix from $1,950 2026-03-31
Vim HIGH 8.6
CVE-2026-34714

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injectio…

Fix: 9.2.0272+
Fix from $1,950 2026-03-30
Unclassified MEDIUM 5.3
CVE-2026-5125

A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file …

Patch available
Fix from $1,600 2026-03-30
Nginx Ui CRITICAL 9.9
CVE-2026-33030

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) …

Fix: after 2.3.3
Fix from $2,300 2026-03-30
Mlflow CRITICAL 9.8
CVE-2025-15379

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to…

Fix: after 3.8.1
Fix from $2,300 2026-03-30
A3300r Firmware HIGH 8.8
CVE-2026-5101

A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the…

No fix yet
Fix from $1,950 2026-03-29
Ghidra HIGH 8.8
CVE-2026-4946

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary comm…

Fix: 12.0.3+
Fix from $1,950 2026-03-29
Unclassified HIGH 8.8
CVE-2026-34005

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the Ho…

Mitigation only
Fix from $1,950 2026-03-29