Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2026-9787 Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-40079 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sani… Cacti 1.2.31+ Fix from $2,3002026-06-25 HIGH 8.8 CVE-2026-8659 OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi… Insightconnect Sqlmap 2.0.1+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-39938 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo… Cacti 1.2.31+ Fix from $2,3002026-06-24 HIGH 8.8 CVE-2026-9772 Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… Unraid 7.3.0+ Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-9773 Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … Unraid 7.3.0+ Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-49980 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --… Rclone 1.74.3+ Fix from $2,3002026-06-24 HIGH 7.7 CVE-2026-54699 Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injecti… Patch available Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-48731 Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i… Patch available Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-48732 Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i… Patch available Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-48703 Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution p… Patch available Fix from $1,9502026-06-24 HIGH 8.0 CVE-2026-48719 Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection i… Patch available Fix from $1,9502026-06-24 MEDIUM 5.0 CVE-2026-57282 Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper s… Git Client 6.6.1+ Fix from $1,6002026-06-24 HIGH 7.8 CVE-2026-12537 Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Act… Gemini Cli 0.1.22 / 0.39.1+ Fix from $1,9502026-06-24 CRITICAL 9.1 CVE-2026-12850 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12851 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12486 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12849 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 HIGH 8.8 CVE-2026-55249 @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewri… Rtk Rewrite Patch available Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-49402 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() hel… Deno 2.7.10+ Fix from $1,9502026-06-23 HIGH 8.8 CVE-2026-35018 NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated a… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-56379 ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $1,9502026-06-23 CRITICAL 9.9 CVE-2026-56274 Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validatio… Flowise 3.1.2+ Fix from $2,3002026-06-23 HIGH 8.7 CVE-2026-11834 A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient vali… Mitigation only Fix from $1,9502026-06-22 MEDIUM 6.3 CVE-2026-12815 A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation le… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.3 CVE-2026-12814 A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_co… Mitigation only Fix from $1,6002026-06-21 HIGH 7.4 CVE-2026-48787 gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature an… Mitigation only Fix from $1,9502026-06-19 HIGH 8.2 CVE-2026-49260 PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the sh… Patch available Fix from $1,9502026-06-19 HIGH 8.6 CVE-2026-12104 OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authen… Mitigation only Fix from $1,9502026-06-19 HIGH 8.6 CVE-2026-40456 An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the … Patch available Fix from $1,9502026-06-18