Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.1 CVE-2026-22313 The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulner… Mitigation only Fix from $2,3002026-06-16 HIGH 8.8 CVE-2026-44932 Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DH… Mitigation only Fix from $1,9502026-06-16 HIGH 7.5 CVE-2026-12398 A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized … Mitigation only Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-5416 Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vuln… Mitigation only Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-12161 Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to ex… Remote Desktop Manager 2026.2.8.0+ Fix from $1,9502026-06-16 HIGH 7.8 CVE-2026-48723 The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable t… Patch available Fix from $1,9502026-06-15 HIGH 8.1 CVE-2026-50874 An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbit… Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-38060 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38061 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38062 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38063 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38064 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38065 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-9862 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w… Core Privileged Access Manager Server 8.1.0.23 / 9.0.0.5+ Fix from $2,3002026-06-15 HIGH 8.8 CVE-2026-9863 Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations.… Core Privileged Access Manager Server 8.1.0.23 / 9.0.0.5+ Fix from $1,9502026-06-15 HIGH 8.6 CVE-2026-11527 Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_fi… Patch available Fix from $1,9502026-06-14 CRITICAL 9.8 CVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Ima… Patch available Fix from $2,3002026-06-14 CRITICAL 9.9 CVE-2026-46716 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem… Mitigation only Fix from $2,3002026-06-12 MEDIUM 6.5 CVE-2026-42853 ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a com… Mitigation only Fix from $1,6002026-06-12 HIGH 7.2 CVE-2026-48163 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11… MariaDB 10.6.27 / 10.11.18+ Fix from $1,9502026-06-12 HIGH 7.2 CVE-2026-48165 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11… MariaDB 10.6.27 / 10.11.18+ Fix from $1,9502026-06-12 HIGH 8.0 CVE-2026-44168 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-44170 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $2,3002026-06-12 HIGH 7.2 CVE-2026-11845 The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote atta… Mitigation only Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-42846 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user… Mitigation only Fix from $2,3002026-06-11 HIGH 8.8 CVE-2026-45172 Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authen… Idira Privileged Session Manager For Ssh 14.0.6 / 14.2.5+ Fix from $1,9502026-06-11 HIGH 7.3 CVE-2026-48547 KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting… Patch available Fix from $1,9502026-06-11 CRITICAL 9.8 CVE-2026-49261 MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8… MariaDB 10.6.27 / 10.11.18+ Fix from $2,3002026-06-11 MEDIUM 5.5 CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect… Imagemagick 6.9.13-48 / 7.1.2-24+ Fix from $1,6002026-06-10 HIGH 7.7 CVE-2026-42563 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `Proc… Patch available Fix from $1,9502026-06-10