Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.1 CVE-2026-48997 e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destinatio… Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-20266 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splun… Ai Toolkit 5.7.4+ Fix from $2,3002026-06-17 CRITICAL 9.6 CVE-2026-55743 The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed… Patch available Fix from $2,3002026-06-17 MEDIUM 6.0 CVE-2026-55748 OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NO… Mitigation only Fix from $1,6002026-06-17 HIGH 7.2 CVE-2026-53876 RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the roo… Mitigation only Fix from $1,9502026-06-17 HIGH 7.2 CVE-2026-11409 An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of us… Tl Wr940n Firmware 260528+ Fix from $1,9502026-06-17 HIGH 7.2 CVE-2026-11410 An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper saniti… Tl Wr940n Firmware 260528+ Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-22313 The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulner… Mitigation only Fix from $2,3002026-06-16 HIGH 8.8 CVE-2026-44932 Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DH… Mitigation only Fix from $1,9502026-06-16 HIGH 7.5 CVE-2026-12398 A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized … Mitigation only Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-5416 Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vuln… Mitigation only Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-12161 Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to ex… Remote Desktop Manager 2026.2.8.0+ Fix from $1,9502026-06-16 HIGH 7.8 CVE-2026-48723 The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable t… Patch available Fix from $1,9502026-06-15 HIGH 8.1 CVE-2026-50874 An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbit… Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-38060 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38061 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38062 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38063 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38064 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38065 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-9862 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w… Core Privileged Access Manager Server 8.1.0.23 / 9.0.0.5+ Fix from $2,3002026-06-15 HIGH 8.8 CVE-2026-9863 Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations.… Core Privileged Access Manager Server 8.1.0.23 / 9.0.0.5+ Fix from $1,9502026-06-15 HIGH 8.6 CVE-2026-11527 Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_fi… Patch available Fix from $1,9502026-06-14 CRITICAL 9.8 CVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Ima… Patch available Fix from $2,3002026-06-14 CRITICAL 9.9 CVE-2026-46716 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem… Mitigation only Fix from $2,3002026-06-12 MEDIUM 6.5 CVE-2026-42853 ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a com… Mitigation only Fix from $1,6002026-06-12 HIGH 7.2 CVE-2026-48163 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11… MariaDB 10.6.27 / 10.11.18+ Fix from $1,9502026-06-12 HIGH 7.2 CVE-2026-48165 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11… MariaDB 10.6.27 / 10.11.18+ Fix from $1,9502026-06-12 HIGH 8.0 CVE-2026-44168 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-44170 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $2,3002026-06-12