Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified CRITICAL 9.8
CVE-2026-71989

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers …

No fix yet
Fix from $5,750 2026-08-09
Unclassified CRITICAL 9.8
CVE-2026-71983

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to…

No fix yet
Fix from $5,750 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71956

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi …

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71954

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71955

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71948

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71949

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71950

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71951

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71952

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71953

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71944

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71945

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71946

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71947

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified MEDIUM 5.4
CVE-2026-48122

Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to v…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-19243

A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.8
CVE-2026-48097

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a co…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.3
CVE-2026-48098

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute p…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.3
CVE-2026-67434

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer …

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.2
CVE-2026-63725

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-con…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-15733EPSS 14%

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attack…

No fix yet
Fix from $2,300 2026-08-06
Virtual Storage Integrator CRITICAL 9.8
CVE-2026-67261

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI …

Fix: 10.11.1.0+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-53975

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands b…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19034

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimit…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.0
CVE-2026-71312

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates r…

No fix yet
Fix from $1,950 2026-08-05
Livebook HIGH 8.0
CVE-2026-66297

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command inject…

Fix: 0.18.7 / 0.19.9+
Fix from $1,950 2026-08-05