Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
520 Firmware HIGH 7.2
CVE-2026-2847EPSS 9%

A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the compone…

No fix yet
Fix from $1,950 2026-02-20
Smanga CRITICAL 9.8
CVE-2025-70831

A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly saniti…

Mitigation only
Fix from $2,300 2026-02-20
Openclaw HIGH 8.8
CVE-2026-26323

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtr…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-27476

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 …

Mitigation only
Fix from $2,300 2026-02-19
Systeminformation HIGH 8.8
CVE-2026-26318

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `l…

Fix: 5.31.0+
Fix from $1,950 2026-02-19
Systeminformation HIGH 7.8
CVE-2026-26280

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetw…

Fix: 5.30.8+
Fix from $1,950 2026-02-19
Trivy Action HIGH 8.1
CVE-2026-26189

Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecur…

Fix: 0.34.1+
Fix from $1,950 2026-02-19
Worktime CRITICAL 9.8
CVE-2025-15559

An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and dow…

Fix: after 11.8.8
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-2686

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. …

Mitigation only
Fix from $2,300 2026-02-19
Unclassified HIGH 7.2
CVE-2026-2670EPSS 16%

A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply o…

Mitigation only
Fix from $1,950 2026-02-18
Majordomo CRITICAL 9.8
CVE-2026-27175EPSS 7%

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is …

Patch available
Fix from $2,300 2026-02-18
Zoneminder CRITICAL 9.8
CVE-2025-65791

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…

Mitigation only
Fix from $2,300 2026-02-18
Unclassified MEDIUM 6.4
CVE-2025-12122

The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortco…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified HIGH 7.3
CVE-2026-2629

A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the f…

Mitigation only
Fix from $1,950 2026-02-17
Unclassified HIGH 8.8
CVE-2026-2630

A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable …

Mitigation only
Fix from $1,950 2026-02-17
Datart HIGH 8.8
CVE-2025-70828

An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

No fix yet
Fix from $1,950 2026-02-17
Unclassified MEDIUM 6.3
CVE-2026-2560

A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoRes…

Mitigation only
Fix from $1,600 2026-02-16
Unclassified HIGH 7.3
CVE-2026-2544

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipu…

Mitigation only
Fix from $1,950 2026-02-16
Filezen HIGH 8.8
CVE-2026-25108 KEV

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted…

Fix: 5.0.11+
Fix from $1,950 2026-02-13
Emp3r0r CRITICAL 9.9
CVE-2026-26068

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is ac…

Fix: 3.21.1+
Fix from $2,300 2026-02-12
Unclassified MEDIUM 5.4
CVE-2026-25828

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $ro…

Mitigation only
Fix from $1,600 2026-02-12
App Lab MEDIUM 6.8
CVE-2026-25933

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the …

Fix: 0.4.0+
Fix from $1,600 2026-02-12
Unclassified HIGH 7.5
CVE-2026-26029

sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to …

Patch available
Fix from $1,950 2026-02-11
Unclassified HIGH 8.8
CVE-2025-65480

An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed wh…

Mitigation only
Fix from $1,950 2026-02-11
Media Streaming Add On HIGH 7.8
CVE-2024-56808

A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained …

Fix: 500.1.1.6+
Fix from $1,950 2026-02-11
Unclassified CRITICAL 9.9
CVE-2026-26009

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server te…

Patch available
Fix from $2,300 2026-02-10
Tapo C260 Firmware HIGH 8.8
CVE-2026-0652EPSS 22%

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchron…

Fix: 1.1.9+
Fix from $1,950 2026-02-10
Axis Os HIGH 8.8
CVE-2025-11142

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be expl…

Fix: 12.7.36+
Fix from $1,950 2026-02-10
Dcs 931l Firmware HIGH 7.2
CVE-2026-2260

A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argu…

Fix: after 1.13.00
Fix from $1,950 2026-02-10
Dir 823x Firmware HIGH 7.2
CVE-2026-2210

A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation l…

No fix yet
Fix from $1,950 2026-02-09