Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-9388 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cste… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9384 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9385 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi… Mitigation only Fix from $2,3002026-05-24 HIGH 7.3 CVE-2026-9367 A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerou… Mitigation only Fix from $1,9502026-05-24 MEDIUM 6.3 CVE-2026-9347 A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the compo… Mitigation only Fix from $1,6002026-05-24 MEDIUM 6.3 CVE-2026-9343 A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of… Mitigation only Fix from $1,6002026-05-23 HIGH 8.1 CVE-2026-9277 shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-esc… Patch available Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-45255 When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the… FreeBSD Mitigation only Fix from $1,9502026-05-21 MEDIUM 6.7 CVE-2026-44076 Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary … Mitigation only Fix from $1,6002026-05-21 HIGH 7.5 CVE-2026-44055 A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execut… Mitigation only Fix from $1,9502026-05-21 HIGH 7.8 CVE-2026-8632 A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalati… Linux Imaging And Printing 3.26.4+ Fix from $1,9502026-05-20 MEDIUM 6.3 CVE-2026-20206 A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute ar… Mitigation only Fix from $1,6002026-05-20 CRITICAL 10.0 CVE-2026-34234 CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-8603 In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system. Scadabr Mitigation only Fix from $2,3002026-05-19 HIGH 8.8 CVE-2026-36828 A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component all… Mitigation only Fix from $1,9502026-05-19 MEDIUM 5.4 CVE-2026-36827 A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/… Mitigation only Fix from $1,6002026-05-19 CRITICAL 9.8 CVE-2026-37281 An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbit… Patch available Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-25244 WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 cont… Webdriverio 9.24.0+ Fix from $2,3002026-05-18 CRITICAL 9.9 CVE-2026-27130 Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 c… Patch available Fix from $2,3002026-05-18 HIGH 7.5 CVE-2026-8767 A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the… Ai after 3.0.97 Fix from $1,9502026-05-17 HIGH 8.8 CVE-2026-45035 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL sc… Tabby 1.0.233+ Fix from $1,9502026-05-15 HIGH 7.0 CVE-2026-45036 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol d… Tabby 1.0.233+ Fix from $1,9502026-05-15 HIGH 7.0 CVE-2026-46483 Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/ta… Vim 9.2.0479+ Fix from $1,9502026-05-15 CRITICAL 10.0 CVE-2026-41553 PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. … Pdf Export Module 0.7.6+ Fix from $2,3002026-05-15 HIGH 8.7 CVE-2026-8654 Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the st… Mitigation only Fix from $1,9502026-05-15 HIGH 8.3 CVE-2026-45369 python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-cont… Mitigation only Fix from $1,9502026-05-14 CRITICAL 9.3 CVE-2026-44666 HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-26191 Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafte… Fleet 4.81.0+ Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-41315 mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to… Mdserver Web after 0.18.4 Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-42589 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON… Gotenberg 8.31.0+ Fix from $2,3002026-05-14