Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.2
CVE-2026-0709

Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid cr…

Mitigation only
Fix from $1,950 2026-01-30
Unity Operating Environment HIGH 7.8
CVE-2026-22277

Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul…

Fix: 5.5.3.0+
Fix from $1,950 2026-01-30
Unity Operating Environment HIGH 7.8
CVE-2026-21418

Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln…

Fix: 5.5.3.0+
Fix from $1,950 2026-01-30
Unclassified MEDIUM 5.4
CVE-2026-1665

A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() function uses eval to execute wg…

Patch available
Fix from $1,600 2026-01-29
Inspektor Gadget HIGH 7.8
CVE-2026-24905

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig…

Fix: 0.48.1+
Fix from $1,950 2026-01-29
Gradle Completion HIGH 7.8
CVE-2026-25063

gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and inc…

Fix: after 9.3.0
Fix from $1,950 2026-01-29
Unclassified CRITICAL 9.8
CVE-2020-37012

Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /a…

Mitigation only
Fix from $2,300 2026-01-29
Unclassified CRITICAL 9.8
CVE-2020-37002

Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execute arbitrary commands after s…

Mitigation only
Fix from $2,300 2026-01-29
Dir 823x Firmware HIGH 8.8
CVE-2026-1544

A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipul…

No fix yet
Fix from $1,950 2026-01-28
Browserstack Local HIGH 7.8
CVE-2025-57283

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly san…

Mitigation only
Fix from $1,950 2026-01-28
Dir 615 Firmware HIGH 7.2
CVE-2026-1506EPSS 5%

A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Co…

No fix yet
Fix from $1,950 2026-01-28
Dir 615 Firmware HIGH 7.2
CVE-2026-1505

A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Fil…

No fix yet
Fix from $1,950 2026-01-28
Dokploy CRITICAL 9.9
CVE-2026-24841

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokp…

Fix: 0.26.6+
Fix from $2,300 2026-01-28
Unclassified HIGH 7.2
CVE-2026-23592

Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code …

Mitigation only
Fix from $1,950 2026-01-27
Unclassified HIGH 7.8
CVE-2025-33234

NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code ex…

Mitigation only
Fix from $1,950 2026-01-27
Dir 615 Firmware HIGH 7.2
CVE-2026-1448EPSS 5%

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component We…

Fix: after 4.10
Fix from $1,950 2026-01-27
Single Sign On Portal System HIGH 8.8
CVE-2026-1428

Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbi…

Mitigation only
Fix from $1,950 2026-01-26
Single Sign On Portal System HIGH 8.8
CVE-2026-1427

Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbi…

Mitigation only
Fix from $1,950 2026-01-26
Note59 Pro\+ Firmware HIGH 7.8
CVE-2025-67264

An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local attacker to…

No fix yet
Fix from $1,950 2026-01-23
Unclassified HIGH 8.8
CVE-2021-47903

LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authent…

No fix yet
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0795

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0796

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0785

ALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0786

ALGO 8180 IP Audio Alerter SCI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware CRITICAL 9.8
CVE-2026-0787

ALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0779

ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0780

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0781

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0782

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0783

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23