Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Eds3016ps1ns Firmware CRITICAL 9.8
CVE-2025-67041

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti…

Mitigation only
Fix from $2,300 2026-03-11
Qts HIGH 7.8
CVE-2024-14026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who h…

Mitigation only
Fix from $1,950 2026-03-11
Arubaos Cx HIGH 7.2
CVE-2026-23816

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the un…

Fix: after 10.17.0001
Fix from $1,950 2026-03-11
Simple Git CRITICAL 9.8
CVE-2026-28292

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacke…

Fix: 3.32.2+
Fix from $2,300 2026-03-10
Fortisandbox Cloud HIGH 7.2
CVE-2026-25836

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, For…

Mitigation only
Fix from $1,950 2026-03-10
Fortiweb HIGH 7.2
CVE-2025-66178

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, …

Fix: 7.0.13 / 7.2.13+
Fix from $1,950 2026-03-10
Unclassified CRITICAL 9.8
CVE-2025-41709

An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.

Mitigation only
Fix from $2,300 2026-03-10
Ghostty HIGH 8.8
CVE-2026-26982

Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used …

Fix: 1.3.0+
Fix from $1,950 2026-03-10
Budibase HIGH 7.2
CVE-2026-25041

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration construc…

Fix: after 3.23.22
Fix from $1,950 2026-03-09
Twake CRITICAL 9.8
CVE-2025-70039

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

Mitigation only
Fix from $2,300 2026-03-09
Archer Axe75 Firmware HIGH 8.0
CVE-2025-15568

A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network…

Fix: 1.3.2+
Fix from $1,950 2026-03-09
N300rh Firmware CRITICAL 9.8
CVE-2026-3696

A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-03-08
Weknora HIGH 8.8
CVE-2026-30861

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an …

Fix: 0.2.10+
Fix from $1,950 2026-03-07
Zikestor Sks8310 8x Firmware CRITICAL 9.8
CVE-2026-25070

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endp…

Fix: after 1.04.b07
Fix from $2,300 2026-03-07
Copilot Command Line Interface HIGH 7.8
CVE-2026-29783

The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter ex…

Fix: 0.0.423+
Fix from $1,950 2026-03-06
Avideo Encoder CRITICAL 9.8
CVE-2026-29058

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj…

Fix: 7.0+
Fix from $2,300 2026-03-06
Known HIGH 7.2
CVE-2026-28507

Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and templa…

Fix: 1.6.4+
Fix from $1,950 2026-03-06
Openclaw CRITICAL 9.8
CVE-2026-28470

OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw MEDIUM 5.5
CVE-2026-28463

OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansio…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28391

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Freepbx HIGH 8.8
CVE-2026-28287EPSS 8%

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu…

Fix: 16.0.20 / 17.0.5+
Fix from $1,950 2026-03-05
Freepbx HIGH 7.2
CVE-2026-28209

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerabi…

Fix: 16.0.20 / 17.0.5+
Fix from $1,950 2026-03-05
Adaptive Security Appliance Software MEDIUM 6.0
CVE-2026-20008

A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …

Fix: 7.0.9 / 7.2.11+
Fix from $1,600 2026-03-04
Tichome Mini Firmware CRITICAL 9.8
CVE-2026-26478

A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craf…

Mitigation only
Fix from $2,300 2026-03-04
Access Commander HIGH 7.2
CVE-2025-59783

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injecti…

Fix: 3.4.2+
Fix from $1,950 2026-03-04
Seppmail CRITICAL 9.8
CVE-2026-27441

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

Fix: 15.0.1+
Fix from $2,300 2026-03-04
Sfx2100 Firmware HIGH 8.8
CVE-2026-28773

The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver We…

No fix yet
Fix from $1,950 2026-03-04
Sfx2100 Firmware HIGH 8.8
CVE-2026-28774

An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series…

No fix yet
Fix from $1,950 2026-03-04
Froxlor CRITICAL 9.1
CVE-2026-26279

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disable…

Fix: 2.3.4+
Fix from $2,300 2026-03-03
Dir 868l Firmware CRITICAL 9.8
CVE-2026-3485

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument…

Mitigation only
Fix from $2,300 2026-03-03