Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
8180 Ip Audio Alerter Firmware HIGH 8.8
CVE-2026-0784

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
Open Webui HIGH 8.8
CVE-2026-0765

Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,950 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0755

gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0756

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified HIGH 8.8
CVE-2026-0757

MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass t…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 7.8
CVE-2026-0758

mcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate pr…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0759

Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2025-15063

Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2025-15061

Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $2,300 2026-01-23
Runtipi HIGH 8.8
CVE-2026-24129

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an …

Fix: 4.7.0+
Fix from $1,950 2026-01-22
Html2pdf CRITICAL 9.8
CVE-2025-56590

An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute …

Mitigation only
Fix from $2,300 2026-01-22
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1324EPSS 6%

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon…

Fix: after 3.0.12
Fix from $2,300 2026-01-22
Unclassified HIGH 7.2
CVE-2026-23699

AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exploited, …

Mitigation only
Fix from $1,950 2026-01-22
Mini Mouse CRITICAL 9.8
CVE-2021-47851

Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP e…

Mitigation only
Fix from $2,300 2026-01-21
Graphql Engine CRITICAL 9.8
CVE-2021-47748

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manip…

Mitigation only
Fix from $2,300 2026-01-21
Cuda Toolkit HIGH 7.3
CVE-2025-33228

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malici…

Fix: 13.1.0+
Fix from $1,950 2026-01-20
Cuda Toolkit HIGH 7.3
CVE-2025-33230

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a …

Fix: 13.1.0+
Fix from $1,950 2026-01-20
Unclassified CRITICAL 9.9
CVE-2026-22844EPSS 13%

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote …

Mitigation only
Fix from $2,300 2026-01-20
Unclassified HIGH 8.8
CVE-2021-47816

Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system c…

No fix yet
Fix from $1,950 2026-01-16
Unclassified HIGH 8.8
CVE-2026-20759

OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user …

Mitigation only
Fix from $1,950 2026-01-16
Zeslecp HIGH 8.8
CVE-2021-47794

ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FTP accounts with shell injecti…

Fix: after 3.1.9
Fix from $1,950 2026-01-16
Arcane HIGH 8.0
CVE-2026-23520

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported …

Fix: 1.13.0+
Fix from $1,950 2026-01-15
Roxy Wi HIGH 7.5
CVE-2026-22265

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in th…

Fix: 8.2.8.2+
Fix from $1,950 2026-01-15
Unclassified CRITICAL 9.8
CVE-2025-62193

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret express…

Patch available
Fix from $2,300 2026-01-15
Nsight Graphics HIGH 7.8
CVE-2025-33206

NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability…

Fix: 2025.5+
Fix from $1,950 2026-01-14
Cursor CRITICAL 9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…

Fix: 2.3+
Fix from $2,300 2026-01-14
Unclassified MEDIUM 6.8
CVE-2026-22718

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

Mitigation only
Fix from $1,600 2026-01-14
Webgrind CRITICAL 9.8
CVE-2023-54339

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter…

Fix: after 1.1
Fix from $2,300 2026-01-13
Tdarr CRITICAL 9.8
CVE-2022-50919

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrar…

Mitigation only
Fix from $2,300 2026-01-13
Unclassified HIGH 8.8
CVE-2022-50909

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to e…

No fix yet
Fix from $1,950 2026-01-13