Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Openclaw HIGH 7.8
CVE-2026-31994

OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handli…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.0
CVE-2026-31995

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism …

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.8
CVE-2026-29607

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypas…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.1
CVE-2026-28460

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to execute non-allowlisted command…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-22176

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variable…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.8
CVE-2026-27566

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatc…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Unclassified CRITICAL 9.8
CVE-2026-30703

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e…

Mitigation only
Fix from $2,300 2026-03-18
Glances HIGH 7.0
CVE-2026-32608

Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that exe…

Fix: 4.5.2+
Fix from $1,950 2026-03-18
Openclaw HIGH 7.2
CVE-2026-22179

OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute …

Fix: 2026.2.22+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 6.7
CVE-2026-22169

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external…

Fix: 2026.2.22+
Fix from $1,600 2026-03-18
Xiaoheifs HIGH 7.2
CVE-2026-28673

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin…

Fix: 0.4.0+
Fix from $1,950 2026-03-18
Roxy Wi HIGH 8.8
CVE-2026-27811

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex…

Fix: 8.2.6.3+
Fix from $1,950 2026-03-18
Es3 Kvm Firmware CRITICAL 9.1
CVE-2026-32298

The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute O…

Mitigation only
Fix from $2,300 2026-03-17
Unclassified HIGH 7.2
CVE-2026-23759

Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection via the restricted shell acce…

Mitigation only
Fix from $1,950 2026-03-17
Ac8 Firmware HIGH 7.2
CVE-2026-4253EPSS 7%

A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of …

No fix yet
Fix from $1,950 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4170

A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/manage…

Mitigation only
Fix from $2,300 2026-03-16
Tl Wr802n Firmware MEDIUM 6.8
CVE-2026-3227

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special e…

Fix: 260303 / 260304+
Fix from $1,600 2026-03-16
Litespeed Web Server HIGH 7.2
CVE-2026-31386

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be ex…

Fix: 6.3.5+
Fix from $1,950 2026-03-16
Mlflow HIGH 8.8
CVE-2025-14287

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 16…

Fix: 3.7.0+
Fix from $1,950 2026-03-16
Unclassified CRITICAL 9.8
CVE-2025-15060

claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-03-16
Deno CRITICAL 9.8
CVE-2026-32260

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_proces…

Fix: 2.7.2+
Fix from $2,300 2026-03-12
Tl Mr6400 Firmware HIGH 8.8
CVE-2026-3841

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by …

Fix: 1.9.0+
Fix from $1,950 2026-03-12
Unclassified CRITICAL 9.4
CVE-2026-28384

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as th…

Patch available
Fix from $2,300 2026-03-12
Unclassified MEDIUM 5.3
CVE-2026-3964

A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Cha…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified MEDIUM 5.3
CVE-2026-3959

A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js…

Mitigation only
Fix from $1,600 2026-03-11
Cloud Cli CRITICAL 9.8
CVE-2026-31975

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection v…

Fix: 1.25.0+
Fix from $2,300 2026-03-11
Cloud Cli HIGH 8.8
CVE-2026-31862

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related A…

Fix: 1.24.0+
Fix from $1,950 2026-03-11
Cursor HIGH 8.8
CVE-2026-31854

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may at…

Fix: 2.0+
Fix from $1,950 2026-03-11
Ios Xr HIGH 8.8
CVE-2026-20040

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underly…

Fix: 25.2.21 / 25.4.2+
Fix from $1,950 2026-03-11
Eds3016ps1ns Firmware CRITICAL 9.8
CVE-2025-70082

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

Mitigation only
Fix from $2,300 2026-03-11