Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2026-0273 A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-6893 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Hos… Mitigation only Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46643 Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/… Mitigation only Fix from $1,9502026-06-10 HIGH 8.5 CVE-2026-9151 An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerabili… Mitigation only Fix from $1,9502026-06-10 MEDIUM 6.9 CVE-2026-46618 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,6002026-06-10 HIGH 7.3 CVE-2026-11417 OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who contro… Mitigation only Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-45564 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>… Mitigation only Fix from $1,9502026-06-10 CRITICAL 9.9 CVE-2026-45556 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45558 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi… Mitigation only Fix from $2,3002026-06-10 HIGH 7.2 CVE-2026-24719 A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc… Qts 5.2.9.3492+ Fix from $1,9502026-06-10 HIGH 7.2 CVE-2026-22893 A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc… Qts 5.2.9.3410+ Fix from $1,9502026-06-10 HIGH 7.2 CVE-2025-66273 A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc… Qts 5.2.9.3410+ Fix from $1,9502026-06-10 HIGH 7.2 CVE-2025-66279 A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator acc… Qts 5.2.9.3410+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-49959 Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands… Patch available Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-38615 DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-25089 KEVEPSS 74% A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0… Fortisandbox 4.4.9 / 5.0.6+ Fix from $2,3002026-06-09 CRITICAL 10.0 CVE-2026-10520 KEVEPSS 100% An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 HIGH 7.2 CVE-2026-10727EPSS 14% An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execut… Mitigation only Fix from $1,9502026-06-09 HIGH 8.7 CVE-2026-9279 Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, … Mitigation only Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-46746 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /ap… Sinec Ins after 1.0 Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-11572 Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user inpu… Patch available Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-40519 Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS comm… Patch available Fix from $1,9502026-06-08 MEDIUM 6.5 CVE-2026-10544 Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated us… Devolutions Server 2026.1.21.0+ Fix from $1,6002026-06-08 HIGH 8.5 CVE-2026-8913 A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled i… Mitigation only Fix from $1,9502026-06-08 HIGH 8.8 CVE-2026-11556 A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the co… Mitigation only Fix from $1,9502026-06-08 HIGH 8.8 CVE-2026-25855 OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by upl… Mitigation only Fix from $1,9502026-06-08 MEDIUM 6.3 CVE-2026-11408 A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of t… Patch available Fix from $1,6002026-06-06 CRITICAL 9.8 CVE-2026-45777 OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remot… Open Xdmod 11.0.3+ Fix from $2,3002026-06-05 MEDIUM 6.0 CVE-2026-25620EPSS 10% An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Ne… Ng Firewall Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.0 CVE-2026-25621 A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure i… Ng Firewall Mitigation only Fix from $1,6002026-06-05