Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2026-19628 A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to … No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-19771 A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component … No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-73667 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates u… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-73660 FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS… No fix yet Fix from $4,9002026-08-13 HIGH 7.6 CVE-2026-73662 FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg1… No fix yet Fix from $4,9002026-08-13 HIGH 8.9 CVE-2026-73570 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-53790 rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying m… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-73623 GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary co… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-73625 GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling gi… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.4 CVE-2026-73483 Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $5,7502026-08-13 MEDIUM 6.1 CVE-2026-17431 PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _styl… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.6 CVE-2026-49481 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d… No fix yet Fix from $5,7502026-08-12 HIGH 7.8 CVE-2026-16695 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci… I Access Client Solutions No fix yet Fix from $4,9002026-08-12 HIGH 7.3 CVE-2026-13476 IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges … Informix Dynamic Server No fix yet Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-73412 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly c… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.2 CVE-2026-73414 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63298 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje… No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-17417 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach… I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-17642 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem… I No fix yet Fix from $4,9002026-08-12 HIGH 7.2 CVE-2026-12005 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access No fix yet Fix from $4,9002026-08-12 HIGH 8.3 CVE-2026-18235 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input val… I after 7.6 Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-17420 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el… I after 7.6 Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-17248 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme… I after 7.6 Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-16956 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements… Db2 Mirror For I after 7.6 Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-16856 IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command. I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-16906 IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization … I No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-48553 Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thr… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-48554 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macr… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-18683 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user… I No fix yet Fix from $4,9002026-08-12