Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.3 CVE-2026-10219 A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge… Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10214 A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools… Patch available Fix from $1,9502026-06-01 HIGH 7.8 CVE-2026-49366 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion Intellij Idea 2026.1.1+ Fix from $1,9502026-05-29 CRITICAL 9.0 CVE-2026-45630 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTra… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45632 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. … Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45633 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /dock… Mitigation only Fix from $2,3002026-05-29 MEDIUM 6.3 CVE-2026-45626 Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeNa… Mitigation only Fix from $1,6002026-05-29 CRITICAL 9.9 CVE-2026-45629 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment We… Mitigation only Fix from $2,3002026-05-29 HIGH 8.8 CVE-2026-45662 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/ser… Mitigation only Fix from $1,9502026-05-29 HIGH 8.8 CVE-2026-45578 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branc… Avideo after 29.0 Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2025-41276 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41277 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 HIGH 7.2 CVE-2025-41279 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $1,9502026-05-29 HIGH 7.8 CVE-2025-41281 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2025-41269 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41270 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41272 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41274 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41275 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 HIGH 7.2 CVE-2025-41266 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $1,9502026-05-29 HIGH 7.2 CVE-2025-41267 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $1,9502026-05-29 HIGH 7.2 CVE-2025-41265 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administr… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $1,9502026-05-29 CRITICAL 9.9 CVE-2026-9645 Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabli… Scadabr Mitigation only Fix from $2,3002026-05-28 HIGH 8.6 CVE-2026-44465 Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the c… Zed 0.227.1+ Fix from $1,9502026-05-28 HIGH 8.6 CVE-2026-44466 Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execut… Zed 0.229.0+ Fix from $1,9502026-05-28 HIGH 7.8 CVE-2026-44463 Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allow… Zed 0.229.0+ Fix from $1,9502026-05-28 HIGH 8.6 CVE-2026-44461 Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment v… Zed 0.227.1+ Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check … Openshift Container Platform 4.21.0+ Fix from $2,3002026-05-28 HIGH 7.0 CVE-2026-44604 A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a s… Mitigation only Fix from $1,9502026-05-28 HIGH 7.8 CVE-2026-45322 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0… Mitigation only Fix from $1,9502026-05-27