Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.3 CVE-2026-13581 A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup o… Mitigation only Fix from $1,6002026-06-29 HIGH 8.8 CVE-2026-55607 Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and nav… Claude Code 2.1.163+ Fix from $1,9502026-06-29 MEDIUM 6.3 CVE-2026-13561 A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the c… Mitigation only Fix from $1,6002026-06-29 MEDIUM 6.3 CVE-2026-13560 A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept … Mitigation only Fix from $1,6002026-06-29 HIGH 8.8 CVE-2026-13545 A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Paramet… Dcs 935l Firmware No fix yet Fix from $1,9502026-06-29 HIGH 7.2 CVE-2026-55975 A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate gener… Mitigation only Fix from $1,9502026-06-26 CRITICAL 10.0 CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 HIGH 7.8 CVE-2026-48778 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by … Notepad\+\+ 8.9.6.1+ Fix from $1,9502026-06-26 HIGH 7.8 CVE-2026-48800 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xm… Notepad\+\+ 8.9.6.1+ Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-32833 Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute… Mitigation only Fix from $1,9502026-06-26 HIGH 8.6 CVE-2026-55441 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.3 CVE-2026-55448 mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local projec… Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.9 CVE-2026-54636 Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku us… Dokku 0.38.7+ Fix from $2,3002026-06-26 CRITICAL 9.0 CVE-2026-45408 Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authentic… Dokku 0.38.2+ Fix from $2,3002026-06-26 HIGH 8.0 CVE-2026-40711 Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an… Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2025-71336 Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feat… Flowise 3.0.6+ Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54088 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $2,3002026-06-25 HIGH 7.8 CVE-2026-46606 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/… Mitigation only Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-55697 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. … Pnpm 10.34.2 / 11.5.3+ Fix from $1,9502026-06-25 HIGH 7.2 CVE-2026-9717 CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution… Powerlogic P7 Firmware 02.004.001.000+ Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-55895 Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the ne… Vim 9.2.0663+ Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-46735 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command (… Display And Peripheral Manager 2.3.0+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-8658 OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands v… Insightconnect Tcpdump 2.0.0+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-8660 OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS c… Insightconnect Ping 1.0.4+ Fix from $2,3002026-06-25 HIGH 8.8 CVE-2026-8664 OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi… Insightconnect Finger 1.0.3+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-8665 OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary O… Insightconnect Translate 2.0.3+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-8666 OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ar… Insightconnect Traceroute 1.0.3+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-8592 OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbit… Insightconnect Awk 1.2.2+ Fix from $2,3002026-06-25 HIGH 8.8 CVE-2026-9155 OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t… Sed Mitigation only Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-8663 OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t… Insightconnect Rpm 1.0.2+ Fix from $1,9502026-06-25