Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-7125 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cs… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7123 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the compon… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7124 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7122 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the … Mitigation only Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-7119 A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of t… Hg3 Firmware No fix yet Fix from $1,9502026-04-27 CRITICAL 9.8 CVE-2026-7121 A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the compone… Mitigation only Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-7096 A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formg… Hg3 Firmware No fix yet Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7066 A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function ex… Mitigation only Fix from $1,9502026-04-27 HIGH 8.8 CVE-2026-33277 An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. Logontracer 2.0.0+ Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7062 A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of t… Mitigation only Fix from $1,9502026-04-26 HIGH 7.3 CVE-2026-7064 A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/brows… Mitigation only Fix from $1,9502026-04-26 HIGH 7.3 CVE-2026-7061 A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/serv… Mitigation only Fix from $1,9502026-04-26 CRITICAL 9.8 CVE-2026-7037 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-04-26 HIGH 7.2 CVE-2026-6992EPSS 6% A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_c… Mr9600 Firmware No fix yet Fix from $1,9502026-04-25 HIGH 8.8 CVE-2026-41421 SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Ele… Mitigation only Fix from $1,9502026-04-24 MEDIUM 6.6 CVE-2026-41411 Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resol… Vim 9.2.0357+ Fix from $1,6002026-04-24 HIGH 8.8 CVE-2026-33208 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-co… Roxy Wi 8.2.6.4+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-6942 radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by by… Radare2 Mcp Server 1.7.0+ Fix from $1,9502026-04-23 CRITICAL 9.8 CVE-2026-41247 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner… Elfinder 2.1.67+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31178 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31181 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31177 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 HIGH 8.8 CVE-2026-41208 Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416… Paperclipai 2026.416.0+ Fix from $1,9502026-04-23 CRITICAL 9.8 CVE-2026-5935 IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma… Total Storage Service Console Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41179EPSS 9% Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to… Rclone 1.73.5+ Fix from $2,3002026-04-23 HIGH 7.8 CVE-2026-40517 radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitra… Radare2 6.1.4+ Fix from $1,9502026-04-22 CRITICAL 9.3 CVE-2026-41064 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f… Avideo after 29.0 Fix from $2,3002026-04-22 CRITICAL 9.9 CVE-2026-40933EPSS 13% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command… Flowise 3.1.0+ Fix from $2,3002026-04-21 HIGH 8.8 CVE-2026-21571 This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1… Bamboo 9.6.25 / 10.2.18+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-31019 In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions rela… Dolibarr Erp\/crm after 22.0.4 Fix from $1,9502026-04-21