Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified MEDIUM 5.3
CVE-2026-16763

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js …

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.4
CVE-2026-47670

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

No fix yet
Fix from $2,300 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16733

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16735

A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file in…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.8
CVE-2026-16287

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Rese…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16631

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component packa…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16630

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16629

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/loc…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16628

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin En…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.8
CVE-2026-14881

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In …

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.8
CVE-2026-44191

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling …

No fix yet
Fix from $1,950 2026-07-22
N8n CRITICAL 9.8
CVE-2026-65590

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandbox…

Fix: 2.29.8+
Fix from $2,300 2026-07-22
Unclassified HIGH 7.8
CVE-2026-44190

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to ex…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 8.8
CVE-2026-3821

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input …

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 5.5
CVE-2026-16492

A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/g…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.0
CVE-2026-16488

A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/conf…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16489

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the comp…

No fix yet
Fix from $1,600 2026-07-22
Maxicharger Single Charger Firmware CRITICAL 9.8
CVE-2026-8986

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious o…

Fix: after 1.03.51
Fix from $2,300 2026-07-21
Maxicharger Single Charger Firmware CRITICAL 9.8
CVE-2026-8985EPSS 7%

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthen…

Fix: after 1.03.51
Fix from $2,300 2026-07-21
Security Center HIGH 8.8
CVE-2026-64881

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-30631

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code vi…

No fix yet
Fix from $2,300 2026-07-21
Security Center CRITICAL 9.9
CVE-2026-64878

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a…

No fix yet
Fix from $2,300 2026-07-21
Security Center CRITICAL 9.9
CVE-2026-64879

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell …

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 7.5
CVE-2026-16445

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, suc…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.2
CVE-2026-6952

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-64625

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-63766

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.9
CVE-2026-54051

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`San…

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.6
CVE-2026-40187

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTem…

No fix yet
Fix from $1,950 2026-07-20