Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21654

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H…

Fix: after 10.22
Fix from $2,300 2026-02-27
Satellite HIGH 8.8
CVE-2026-0980

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with …

Fix: after 0.12.1
Fix from $1,950 2026-02-27
N300rh Firmware CRITICAL 9.8
CVE-2026-3301

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file …

Mitigation only
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25196

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25721

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-3037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25037

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-25105

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code e…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20764

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-23702

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-24452

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-24695

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code ex…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-25109

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-25111

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware MEDIUM 6.6
CVE-2026-25195

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exe…

Fix: after 1.12.1
Fix from $1,600 2026-02-27
Xweb 500b Pro Firmware HIGH 7.2
CVE-2026-24517

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 500b Pro Firmware CRITICAL 9.8
CVE-2026-24663

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code exec…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Xweb 500b Pro Firmware HIGH 8.8
CVE-2026-24689

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20742

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20902

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exe…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-20910

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Xweb 300d Pro Firmware HIGH 8.8
CVE-2026-21389

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut…

Fix: after 1.12.1
Fix from $1,950 2026-02-27
Osctrl HIGH 8.4
CVE-2026-28279

osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment conf…

Fix: 0.5.0+
Fix from $1,950 2026-02-26
Kiteworks HIGH 8.8
CVE-2026-28269

Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated u…

Fix: 9.2.0+
Fix from $1,950 2026-02-26
Zen C HIGH 7.3
CVE-2026-28207

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78)…

Fix: 0.4.2+
Fix from $1,950 2026-02-26
Vitess CRITICAL 9.9
CVE-2026-27965

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…

Fix: 22.0.4 / 23.0.3+
Fix from $2,300 2026-02-26
Unclassified HIGH 7.7
CVE-2026-27938

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workfl…

Patch available
Fix from $1,950 2026-02-26
Manyfold HIGH 8.8
CVE-2026-27635

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version…

Fix: 0.133.0+
Fix from $1,950 2026-02-26
Tinyweb CRITICAL 9.8
CVE-2026-27613

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers …

Fix: 2.01+
Fix from $2,300 2026-02-25
Oneuptime HIGH 8.8
CVE-2026-27728

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMo…

Fix: 10.0.7+
Fix from $1,950 2026-02-25