Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
App Connect Enterprise CRITICAL 9.8
CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
Unclassified HIGH 8.3
CVE-2026-22621

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administ…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.8
CVE-2026-22622

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to …

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.8
CVE-2026-44106

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as roo…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.8
CVE-2026-44099

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting …

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.8
CVE-2026-44093

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands …

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.8
CVE-2026-44095

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as r…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.8
CVE-2026-44096

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compro…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.6
CVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injectio…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.8
CVE-2026-16524

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed valid…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.6
CVE-2026-67438

OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go ch…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.8
CVE-2026-56389

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration var…

No fix yet
Fix from $1,600 2026-07-29
Aspera Faspex HIGH 7.2
CVE-2026-14958

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 7.2
CVE-2026-14959

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.2
CVE-2026-59764

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an …

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.2
CVE-2026-61376

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exp…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-54540

Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 8.8
CVE-2026-55578

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses a…

No fix yet
Fix from $1,950 2026-07-27
Unclassified CRITICAL 9.9
CVE-2026-48030EPSS 5%

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability i…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 7.8
CVE-2026-24252

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead …

No fix yet
Fix from $1,950 2026-07-27
Velocloud Orchestrator CRITICAL 10.0
CVE-2026-16812 KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…

Fix: 5.2.3.14 / 6.1.3.4+
Fix from $2,300 2026-07-27
Unclassified HIGH 8.5
CVE-2025-59172

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacke…

No fix yet
Fix from $1,950 2026-07-27
Connection Manager For Objectscale HIGH 8.4
CVE-2026-59687

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…

Fix: 7.2.54.19 / 7.2.63.3+
Fix from $1,950 2026-07-27
Connection Manager For Objectscale HIGH 8.4
CVE-2026-59688

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…

Fix: 7.2.54.19 / 7.2.63.3+
Fix from $1,950 2026-07-27
Connection Manager For Objectscale HIGH 8.4
CVE-2026-59686

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…

Fix: 7.2.54.19 / 7.2.63.3+
Fix from $1,950 2026-07-27
Unclassified HIGH 8.3
CVE-2026-17497

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the defa…

No fix yet
Fix from $1,950 2026-07-26
Unclassified CRITICAL 9.8
CVE-2026-16766

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly t…

No fix yet
Fix from $2,300 2026-07-25
Unclassified HIGH 7.2
CVE-2026-65711

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.2
CVE-2026-66138

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic…

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.9
CVE-2026-63732

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation…

No fix yet
Fix from $2,300 2026-07-23