Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-8500 Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpass… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44194EPSS 6% OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens… Opnsense 26.1.8+ Fix from $2,3002026-05-13 HIGH 7.2 CVE-2026-0261 Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-05-13 HIGH 8.8 CVE-2026-6281 A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local networ… Mitigation only Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-42924 An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.8 CVE-2026-42290 protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input… Protobufjs Cli 1.2.1 / 2.0.2+ Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-34176 When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 CRITICAL 9.8 CVE-2026-42062 ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arb… Mitigation only Fix from $2,3002026-05-13 HIGH 7.2 CVE-2026-35506 ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a craft… Mitigation only Fix from $1,9502026-05-13 HIGH 7.2 CVE-2026-43685 A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system com… Filemaker Cloud 2.22.0.5+ Fix from $1,9502026-05-12 CRITICAL 9.3 CVE-2026-44258 efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and hom… Mitigation only Fix from $2,3002026-05-12 HIGH 7.2 CVE-2026-23820 A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execu… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-23821 A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system … Arubaos 8.10.0.0 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-41613 Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.119.1+ Fix from $1,9502026-05-12 MEDIUM 6.7 CVE-2025-53870 An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, … Fortiap 7.2.6 / 7.4.5+ Fix from $1,6002026-05-12 MEDIUM 6.7 CVE-2025-53680 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiA… Fortiap 7.0.6 / 7.4.5+ Fix from $1,6002026-05-12 HIGH 8.4 CVE-2026-43991 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check… Patch available Fix from $1,9502026-05-12 HIGH 8.4 CVE-2026-43990 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command … Patch available Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31226 The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) i… Mitigation only Fix from $2,3002026-05-12 HIGH 7.2 CVE-2026-8051 OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve … Virtual Traffic Manager after 22.8 Fix from $1,9502026-05-12 HIGH 8.2 CVE-2026-35071 Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command I… Insightiq 6.3.0+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2025-40947 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX … Ruggedcom Rox Mx5000 Firmware 2.17.1+ Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2025-40949 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX … Ruggedcom Rox Mx5000 Firmware 2.17.1+ Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-7256 ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow… Wre6505 Firmware Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-45391 A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary command… Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-45393 A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr… Mitigation only Fix from $1,9502026-05-12 HIGH 8.1 CVE-2026-30635 Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in t… Mitigation only Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-7816 OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy… Pgadmin 4 9.15+ Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-31246 GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the Executor.run()… Mitigation only Fix from $1,6002026-05-11 HIGH 8.0 CVE-2026-4802 A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized… Mitigation only Fix from $1,9502026-05-11