Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Godot Mcp HIGH 7.8
CVE-2026-25546

Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerabil…

Fix: 0.1.1+
Fix from $1,950 2026-02-04
Group Office HIGH 8.8
CVE-2026-25512EPSS 19%

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote …

Fix: 6.8.150 / 25.0.82+
Fix from $1,950 2026-02-04
Melange HIGH 7.8
CVE-2026-25143

melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to…

Fix: 0.40.5+
Fix from $1,950 2026-02-04
Openclaw HIGH 7.5
CVE-2026-25157

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeC…

Fix: 2026.1.29+
Fix from $1,950 2026-02-04
Melange HIGH 8.8
CVE-2026-24844

melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input …

Fix: after 0.40.5
Fix from $1,950 2026-02-04
N8n HIGH 7.2
CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s…

Fix: 1.120.3+
Fix from $1,950 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25053

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users…

Fix: 1.123.0 / 2.5.0+
Fix from $2,300 2026-02-04
Claude Code HIGH 8.8
CVE-2026-24887

Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirm…

Fix: 2.0.72+
Fix from $1,950 2026-02-03
Aion CRITICAL 9.8
CVE-2025-52626

A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actio…

Mitigation only
Fix from $2,300 2026-02-03
Wrc X1500gsa B Firmware HIGH 8.8
CVE-2026-22550

OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS comman…

Fix: after 1.13
Fix from $1,950 2026-02-03
Fabric Operating System HIGH 7.8
CVE-2026-0383

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely store…

Fix: 9.2.1c2 / 9.2.2b+
Fix from $1,950 2026-02-03
Openclaw HIGH 8.8
CVE-2026-24763

OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed i…

Fix: 2026.1.29+
Fix from $1,950 2026-02-02
Signal K Server HIGH 8.8
CVE-2026-23515

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated …

Fix: 1.5.0+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-22223

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22224

A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22225

A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2  and Arche…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22226

A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22227

A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22229

A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-22221

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-22222

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code.…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-0630

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to e…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-0631

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Unclassified HIGH 8.0
CVE-2025-9974

The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-l…

Mitigation only
Fix from $1,950 2026-02-02
Unclassified HIGH 8.8
CVE-2026-24788

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by …

Mitigation only
Fix from $1,950 2026-02-02
Wing Ftp Server HIGH 8.8
CVE-2020-37032

Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system c…

No fix yet
Fix from $1,950 2026-01-30
Unclassified CRITICAL 9.8
CVE-2020-37027

Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.6
CVE-2026-25130

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple…

Patch available
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.2
CVE-2026-1723

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…

Mitigation only
Fix from $2,300 2026-01-30
Runcommand CRITICAL 9.8
CVE-2025-51958

aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcomm…

Mitigation only
Fix from $2,300 2026-01-30