Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.0 CVE-2026-25622EPSS 10% A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On … Ng Firewall 17.4.1+ Fix from $1,6002026-06-05 MEDIUM 6.0 CVE-2026-25623EPSS 6% An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generati… Ng Firewall 17.4.1+ Fix from $1,6002026-06-05 HIGH 7.7 CVE-2026-46394 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git… Mitigation only Fix from $1,9502026-06-05 CRITICAL 9.4 CVE-2026-46399 HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file ove… Mitigation only Fix from $2,3002026-06-05 HIGH 8.8 CVE-2026-49492 Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken … Mitigation only Fix from $1,9502026-06-05 CRITICAL 9.0 CVE-2026-45750 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi… Termix 2.3.2+ Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-45748 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint… Termix 2.3.2+ Fix from $2,3002026-06-05 CRITICAL 9.9 CVE-2026-45744 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi… Termix 2.3.2+ Fix from $2,3002026-06-05 MEDIUM 6.3 CVE-2026-11341 A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipu… Mitigation only Fix from $1,6002026-06-05 HIGH 8.8 CVE-2026-21837 HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary o… Digital Experience Mitigation only Fix from $1,9502026-06-05 HIGH 7.2 CVE-2026-10872 A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. P… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10873 A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Exec… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10871 A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the compo… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-10870 A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulati… Mitigation only Fix from $1,9502026-06-04 HIGH 8.2 CVE-2025-69755 An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a … Mitigation only Fix from $1,9502026-06-04 HIGH 7.5 CVE-2026-10796 nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands … Node Version Manager 0.40.5+ Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2025-67447 The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does n… Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.6 CVE-2026-35906 An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary … Mitigation only Fix from $2,3002026-06-04 HIGH 8.7 CVE-2026-45431 This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web manageme… Mitigation only Fix from $1,9502026-06-04 HIGH 7.2 CVE-2026-3820 There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject… Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.8 CVE-2026-50206 Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files. Connect M6e 5g Firmware Mitigation only Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-49190 The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installa… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.7 CVE-2026-10805 A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malform… Mitigation only Fix from $1,6002026-06-04 CRITICAL 9.8 CVE-2026-49185 The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 HIGH 8.2 CVE-2026-41010 ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name retu… Mitigation only Fix from $1,9502026-06-04 HIGH 8.2 CVE-2026-41011 PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['nam… No fix yet Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-36576 An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arb… Mitigation only Fix from $2,3002026-06-03 HIGH 8.0 CVE-2026-47294 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attack… Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10279 A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts … Mitigation only Fix from $1,6002026-06-01 HIGH 7.3 CVE-2026-10273 A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webho… Patch available Fix from $1,9502026-06-01