Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
X6000r Firmware HIGH 8.8
CVE-2026-4611

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file …

Mitigation only
Fix from $1,950 2026-03-23
Blinko HIGH 7.2
CVE-2026-23882

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying…

Fix: 1.8.4+
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33648

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding u…

Fix: after 26.0
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 7.2
CVE-2025-15518

Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 7.2
CVE-2025-15519

Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Avideo CRITICAL 10.0
CVE-2026-33478EPSS 13%

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget…

Fix: after 26.0
Fix from $2,300 2026-03-23
Avideo HIGH 8.1
CVE-2026-33482

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/…

Fix: after 26.0
Fix from $1,950 2026-03-23
Unclassified CRITICAL 9.8
CVE-2026-4585

A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.8
CVE-2026-32968

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in …

Mitigation only
Fix from $2,300 2026-03-23
Mr9600 Firmware HIGH 8.8
CVE-2026-4558

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipu…

No fix yet
Fix from $1,950 2026-03-22
Avideo HIGH 7.5
CVE-2026-33319

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin construc…

Fix: 26.0+
Fix from $1,950 2026-03-22
F453 Firmware HIGH 8.8
CVE-2026-4554

A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The …

No fix yet
Fix from $1,950 2026-03-22
Openclaw CRITICAL 9.8
CVE-2026-32056

OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac…

Fix: 2026.2.22+
Fix from $2,300 2026-03-21
Dynaconf HIGH 8.1
CVE-2026-33154

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due …

Fix: 3.2.13+
Fix from $1,950 2026-03-20
Debian Linux HIGH 7.8
CVE-2025-63261

AWStats 8.0 is vulnerable to Command Injection via the open function

No fix yet
Fix from $1,950 2026-03-20
Dir 820lw Firmware CRITICAL 9.8
CVE-2026-4499

A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le…

Mitigation only
Fix from $2,300 2026-03-20
Unclassified MEDIUM 5.3
CVE-2026-4496

A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function ch…

Patch available
Fix from $1,600 2026-03-20
Wa300 Firmware CRITICAL 9.8
CVE-2026-4497

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22897

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra…

Fix: 2.0.4.0415+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22901

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: after 2.0.5.0906
Fix from $2,300 2026-03-20
Qunetswitch MEDIUM 6.7
CVE-2026-22902

A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit …

Fix: after 2.0.5.0906
Fix from $1,600 2026-03-20
Sqlbot HIGH 8.8
CVE-2026-32950

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab…

Fix: 1.7.0+
Fix from $1,950 2026-03-20
Dir 513 Firmware HIGH 8.8
CVE-2026-4465

A flaw has been found in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formSysCmd. Executing a manipulation of…

No fix yet
Fix from $1,950 2026-03-20
Openclaw HIGH 8.1
CVE-2026-32034

OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled an…

Fix: 2026.2.21+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.8
CVE-2026-32010

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exe…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.2
CVE-2026-32003

OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypa…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Bing Images CRITICAL 9.8
CVE-2026-32191

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…

Mitigation only
Fix from $2,300 2026-03-19
Openemr CRITICAL 9.1
CVE-2026-32238

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command …

Fix: 8.0.0.2+
Fix from $2,300 2026-03-19
Openclaw HIGH 7.8
CVE-2026-31999

OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.…

Fix: 2026.3.1+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32000

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallba…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19