Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 5.3 CVE-2026-15669 A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go … Mitigation only Fix from $1,6002026-07-14 CRITICAL 9.8 CVE-2026-60121 Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers… Flamingo after 4.12.2 Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-61498 Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote una… Flamingo after 4.12.2 Fix from $2,3002026-07-13 HIGH 8.6 CVE-2026-22100 The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be execute… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-15546 A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. … Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15547 A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15513 A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Perform… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.8 CVE-2026-15511 A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of th… Mitigation only Fix from $2,3002026-07-12 MEDIUM 6.3 CVE-2026-15495 A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java… No fix yet Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15496 A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/mai… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15487 A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmwa… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15486 A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component F… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15485 A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the compo… Mitigation only Fix from $1,6002026-07-12 HIGH 8.8 CVE-2025-30007 HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary… Control Panel 1.9.5+ Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-54149 MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP r… Mitigation only Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-61434 PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted com… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.1 CVE-2026-56688 Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inject… Powerflex Manager 4.5.5.2 / 5.1.0.1+ Fix from $2,3002026-07-10 CRITICAL 9.0 CVE-2026-41880 R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-… Mitigation only Fix from $2,3002026-07-10 HIGH 8.7 CVE-2026-41876 R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file… Mitigation only Fix from $1,9502026-07-10 HIGH 7.2 CVE-2026-0286 A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute ar… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-07-09 HIGH 7.2 CVE-2026-59721 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts… Patch available Fix from $1,9502026-07-09 CRITICAL 10.0 CVE-2026-59726 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp… Patch available Fix from $2,3002026-07-09 HIGH 8.8 CVE-2026-59734 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/Appli… Patch available Fix from $1,9502026-07-09 HIGH 8.1 CVE-2026-55420 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, proce… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,9502026-07-09 CRITICAL 9.6 CVE-2026-58459 gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS… Gpsd after 3.27.5 Fix from $2,3002026-07-09 MEDIUM 5.3 CVE-2026-15193 A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/mai… Patch available Fix from $1,6002026-07-09 HIGH 7.8 CVE-2026-41857 A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh … Bosh Cli 7.10.5+ Fix from $1,9502026-07-09 HIGH 8.5 CVE-2026-55849 @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --work… Patch available Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-60102 Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCom… Patch available Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-24700 An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W … Rv130 Firmware No fix yet Fix from $1,9502026-07-08