Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2026-27849

Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normall…

Mitigation only
Fix from $2,300 2026-02-25
Unclassified MEDIUM 6.7
CVE-2026-20099

A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local …

Mitigation only
Fix from $1,600 2026-02-25
Unclassified MEDIUM 6.5
CVE-2026-20036

A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with valid …

Mitigation only
Fix from $1,600 2026-02-25
Unclassified CRITICAL 9.8
CVE-2026-27848

Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as…

Mitigation only
Fix from $2,300 2026-02-25
Olivetin CRITICAL 9.9
CVE-2026-27626

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec…

Fix: after 3000.10.0
Fix from $2,300 2026-02-25
Masterscada CRITICAL 9.8
CVE-2026-22553

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that…

Mitigation only
Fix from $2,300 2026-02-24
10g08 0800gsm Firmware HIGH 8.8
CVE-2026-23678

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnosti…

Mitigation only
Fix from $1,950 2026-02-24
Tip 635g Firmware HIGH 8.8
CVE-2026-3101EPSS 6%

A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation res…

No fix yet
Fix from $1,950 2026-02-24
Exiftool HIGH 8.8
CVE-2026-3102

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm…

Fix: 13.50+
Fix from $1,950 2026-02-24
Api Gateway Deploy HIGH 7.8
CVE-2026-27208

bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and P…

Mitigation only
Fix from $1,950 2026-02-24
Yt Dlp HIGH 8.8
CVE-2026-26331

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-…

Fix: 2026.02.21+
Fix from $1,950 2026-02-24
Wx5610 B0 Firmware CRITICAL 9.8
CVE-2025-13942

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attack…

Fix: 1.00 / 1.16+
Fix from $2,300 2026-02-24
Ex5601 T1 Firmware HIGH 8.8
CVE-2025-13943

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)…

Fix: 5.17 / 5.18+
Fix from $1,950 2026-02-24
Vmg3625 T50c Firmware HIGH 7.2
CVE-2026-1459

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions thro…

Fix: after 5.50
Fix from $1,950 2026-02-24
Vigor300b Firmware HIGH 7.2
CVE-2026-3040EPSS 9%

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload…

Fix: after 1.5.1.6
Fix from $1,950 2026-02-23
X6000r Firmware HIGH 8.8
CVE-2025-70328

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executa…

No fix yet
Fix from $1,950 2026-02-23
X5000r Firmware HIGH 8.0
CVE-2025-70329

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable…

No fix yet
Fix from $1,950 2026-02-23
Vaelsys CRITICAL 9.8
CVE-2026-2952EPSS 7%

A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request …

Mitigation only
Fix from $2,300 2026-02-22
Online Store Management System CRITICAL 9.8
CVE-2026-2944EPSS 6%

A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file …

Mitigation only
Fix from $2,300 2026-02-22
Openclaw HIGH 8.0
CVE-2026-27487

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a…

Fix: 2026.2.14+
Fix from $1,950 2026-02-21
Moodle HIGH 7.2
CVE-2026-26046

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command in…

Fix: 4.5.9 / 5.0.5+
Fix from $1,950 2026-02-21
Nagios Xi HIGH 8.8
CVE-2026-2041EPSS 73%

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2026-2042EPSS 6%

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2026-2043EPSS 73%

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.8
CVE-2026-2035

Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …

Patch available
Fix from $1,600 2026-02-20
Thesystem CRITICAL 9.8
CVE-2019-25441EPSS 8%

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting mal…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified MEDIUM 6.3
CVE-2026-27113

Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3ea…

Patch available
Fix from $1,600 2026-02-20
Deno CRITICAL 9.8
CVE-2026-27190

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process impl…

Fix: 2.6.8+
Fix from $2,300 2026-02-20
Unclassified CRITICAL 10.0
CVE-2021-35402

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter…

Mitigation only
Fix from $2,300 2026-02-20
520 Firmware HIGH 7.2
CVE-2026-2846EPSS 10%

A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of…

No fix yet
Fix from $1,950 2026-02-20