Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2026-9208 Tanium addressed an unauthorized code execution vulnerability in Connect. Connect 5.26.191 / 5.29.237+ Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-45152 uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe … Mitigation only Fix from $1,9502026-05-27 HIGH 8.2 CVE-2026-44712 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the confi… Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-44713 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment vari… Mitigation only Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-45136 claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) int… Claude Code Cache Fix 3.5.2+ Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-44709 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP en… Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.3 CVE-2026-44590 Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.… Mitigation only Fix from $2,3002026-05-27 HIGH 7.8 CVE-2026-44724 systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command inj… Mitigation only Fix from $1,9502026-05-27 CRITICAL 10.0 CVE-2026-45087 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf… Mitigation only Fix from $2,3002026-05-27 HIGH 8.8 CVE-2026-44345 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/con… Bentoml 1.4.39+ Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-44346 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam… Bentoml 1.4.39+ Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-36044 @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/… Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-36045 picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function atte… Mitigation only Fix from $1,9502026-05-27 HIGH 7.2 CVE-2026-40852 A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly ch… Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.1 CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(… Patch available Fix from $2,3002026-05-27 HIGH 8.8 CVE-2026-9207 Tanium addressed an unauthorized code execution vulnerability in Connect. Connect 5.26.191 / 5.29.237+ Fix from $1,9502026-05-27 CRITICAL 9.1 CVE-2026-44444 Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts… Mitigation only Fix from $2,3002026-05-26 HIGH 7.8 CVE-2026-9560 Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with eleva… Connect 3.8.2+ Fix from $1,9502026-05-26 CRITICAL 9.9 CVE-2026-46624 Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL … Twenty 1.16.7+ Fix from $2,3002026-05-26 HIGH 8.1 CVE-2026-48694 FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_… Fastnetmon after 1.2.9 Fix from $1,9502026-05-26 HIGH 8.1 CVE-2026-48695 FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() funct… Fastnetmon after 1.2.9 Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-9565 A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/age… Mitigation only Fix from $1,6002026-05-26 CRITICAL 9.9 CVE-2026-44723 Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly i… Vowpal Wabbit 2026-05-04+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-48687 FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() functi… Fastnetmon after 1.2.9 Fix from $2,3002026-05-26 CRITICAL 9.0 CVE-2026-4480EPSS 14% A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print… Openshift Container Platform 4.2.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-9543 A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of th… Mitigation only Fix from $2,3002026-05-26 MEDIUM 6.3 CVE-2026-9532EPSS 11% A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bi… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-9533EPSS 11% A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi o… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-9534EPSS 11% A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Se… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-9531EPSS 11% A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the compo… Mitigation only Fix from $1,6002026-05-26