Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified MEDIUM 5.3
CVE-2026-5023

A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function …

Mitigation only
Fix from $1,600 2026-03-29
Unclassified HIGH 7.3
CVE-2026-5012

A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing a manipulation can lead to os…

Mitigation only
Fix from $1,950 2026-03-28
Unclassified MEDIUM 5.3
CVE-2026-5007

A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file src/index.ts of the component…

Mitigation only
Fix from $1,600 2026-03-28
Authenticator HIGH 7.8
CVE-2026-33874

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, …

Fix: 4.16.0+
Fix from $1,950 2026-03-27
Web Interface CRITICAL 9.8
CVE-2026-33765

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 …

Fix: 6.0+
Fix from $2,300 2026-03-27
Fleet CRITICAL 9.8
CVE-2026-34387

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an …

Fix: 4.81.1+
Fix from $2,300 2026-03-27
Coderider CRITICAL 10.0
CVE-2026-30302

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffec…

Fix: after 2.3.6
Fix from $2,300 2026-03-27
Axon Code CRITICAL 9.8
CVE-2026-30303

The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective.…

Fix: after 4.123.1
Fix from $2,300 2026-03-27
Aterm Wg2600hs Firmware CRITICAL 9.8
CVE-2026-4622

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

Fix: 1.3.2 / 1.4.2+
Fix from $2,300 2026-03-27
Aterm Wx3600hp Firmware CRITICAL 9.8
CVE-2026-4620

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

Fix: 1.4.2 / 1.5.3+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-27650

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be execut…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Openhands CRITICAL 9.9
CVE-2026-33718

OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method a…

Fix: 1.5.0+
Fix from $2,300 2026-03-27
Pinchtab HIGH 7.2
CVE-2026-33623

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command inj…

Fix: 0.8.5+
Fix from $1,950 2026-03-26
Unclassified HIGH 7.5
CVE-2023-7338

Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to e…

Mitigation only
Fix from $1,950 2026-03-26
Thingino Firmware CRITICAL 9.8
CVE-2026-26213EPSS 6%

thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive p…

Fix: after 2026-03-15
Fix from $2,300 2026-03-26
Oneuptime CRITICAL 9.9
CVE-2026-33396

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can …

Fix: 10.0.35+
Fix from $2,300 2026-03-26
Unclassified HIGH 8.0
CVE-2026-1961

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vuln…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 8.8
CVE-2026-4840EPSS 11%

A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cg…

Mitigation only
Fix from $1,950 2026-03-26
Asus Firmware HIGH 8.8
CVE-2025-15101

An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to exe…

Fix: after 3.0.0.6_102
Fix from $1,950 2026-03-26
Modoboa HIGH 7.2
CVE-2026-27602

Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls wit…

Fix: 2.7.1+
Fix from $1,950 2026-03-25
Textract CRITICAL 9.8
CVE-2026-26831

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious…

Fix: after 2.5.0
Fix from $2,300 2026-03-25
Tesseract Ocr CRITICAL 9.8
CVE-2026-26832

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in sr…

Fix: after 2.2.1
Fix from $2,300 2026-03-25
Thumbler CRITICAL 9.8
CVE-2026-26833

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c…

Fix: after 1.1.2
Fix from $2,300 2026-03-25
Vim HIGH 7.3
CVE-2026-33412

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix…

Fix: 9.2.0202+
Fix from $1,950 2026-03-24
Sbt HIGH 7.8
CVE-2026-32948

sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run V…

Fix: 1.12.7+
Fix from $1,950 2026-03-24
Unclassified HIGH 7.7
CVE-2026-23920

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchor…

Mitigation only
Fix from $1,950 2026-03-24
Intake HIGH 8.8
CVE-2026-33310

Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default v…

Fix: 2.0.9+
Fix from $1,950 2026-03-24
Langflow CRITICAL 9.1
CVE-2026-33475

Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in mult…

Fix: 1.9.0+
Fix from $2,300 2026-03-24
Unclassified HIGH 7.2
CVE-2026-4627

A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_mod…

Mitigation only
Fix from $1,950 2026-03-24
Indico HIGH 8.8
CVE-2026-33046

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to …

Fix: 3.3.12+
Fix from $1,950 2026-03-23