Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified MEDIUM 6.9
CVE-2026-70611

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Langflow HIGH 8.8
CVE-2026-17625

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17623

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the com…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Qradar Security Information And Event Manager HIGH 8.8
CVE-2026-13477

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-71284

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's fil…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.8
CVE-2026-16022

@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through s…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71243

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd =…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70374

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateT…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70375

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-18900

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This man…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-66902

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable sub…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 8.8
CVE-2026-16793

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.2
CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-51190

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL e…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-52102

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as ro…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.2
CVE-2026-67599

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary comma…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.3
CVE-2026-18641

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the fu…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.8
CVE-2026-69096

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) con…

Mitigation only
Fix from $1,950 2026-08-03
Unclassified HIGH 7.2
CVE-2026-67608

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_au…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-18590

A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin …

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.5
CVE-2026-18587

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a m…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-67324

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default …

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 8.8
CVE-2026-67325

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. A…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.3
CVE-2026-67308

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi…

No fix yet
Fix from $2,300 2026-08-01
Archer Axe75 Firmware HIGH 8.0
CVE-2026-9044

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated atta…

Fix: 1.5.6+
Fix from $1,950 2026-07-31
Pgadmin 4 CRITICAL 9.9
CVE-2026-17566

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passi…

Fix: 9.18+
Fix from $2,300 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-17347

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption…

Fix: 9.17+
Fix from $1,950 2026-07-31
Unclassified HIGH 7.2
CVE-2026-16843

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid crede…

No fix yet
Fix from $1,950 2026-07-31
Hardware Management Console CRITICAL 9.8
CVE-2026-12943

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…

Fix: 10.3.1064.1 / 11.1.1112.1+
Fix from $2,300 2026-07-30
Langflow CRITICAL 9.8
CVE-2026-12940

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C…

Fix: 1.10.2+
Fix from $2,300 2026-07-30