Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2026-40520 FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation … Api 17.0.8+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-41036 This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authen… Qn I 470 Firmware Patch available Fix from $1,9502026-04-21 CRITICAL 9.8 CVE-2026-5965 NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands an… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-32311 Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a u… Flowsint Patch available Fix from $2,3002026-04-20 HIGH 7.2 CVE-2026-24506 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.70+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-26942 Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command … Powerprotect Dp Series Appliance 2.7.9 / 8.6.1.0+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-26943 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.70+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-22761 Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access coul… Powerprotect Dp Series Appliance 2.7.9 / 8.6.1.0+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-23774 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.50+ Fix from $1,9502026-04-20 HIGH 8.8 CVE-2026-5967 ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can injec… Threatsonar Anti Ransomware 4.0.0+ Fix from $1,9502026-04-20 CRITICAL 9.1 CVE-2026-6644 A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r… Data Master 4.3.3.RR42 / 5.1.2.reo1+ Fix from $2,3002026-04-20 HIGH 8.8 CVE-2026-35582 Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection beca… Emissary 8.43.0+ Fix from $1,9502026-04-18 HIGH 7.8 CVE-2026-40527 radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malici… Radare2 6.1.6+ Fix from $1,9502026-04-17 MEDIUM 6.3 CVE-2026-33145 xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsa… Xrdp 0.10.6+ Fix from $1,6002026-04-17 CRITICAL 9.1 CVE-2026-23500 Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT … Dolibarr Erp\/crm 23.0.0+ Fix from $2,3002026-04-17 HIGH 7.2 CVE-2026-6483EPSS 14% A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. … Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.7 CVE-2026-35072 Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.70+ Fix from $1,6002026-04-17 MEDIUM 6.7 CVE-2026-35073 Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20… Data Domain Operating System 7.13.1.70 / 8.3.1.30+ Fix from $1,6002026-04-17 MEDIUM 6.7 CVE-2026-35074 Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.70+ Fix from $1,6002026-04-17 HIGH 7.2 CVE-2026-21719 An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitr… Cubecart 6.6.0+ Fix from $1,9502026-04-17 HIGH 8.1 CVE-2026-41113 sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c. Patch available Fix from $1,9502026-04-16 CRITICAL 9.8 CVE-2026-6349 The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS command… Mitigation only Fix from $2,3002026-04-16 HIGH 7.4 CVE-2026-41015 radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed… Patch available Fix from $1,9502026-04-16 HIGH 7.8 CVE-2026-40176 Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce… Composer after 2.9.5 Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-40261 Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce… Composer after 2.9.5 Fix from $1,9502026-04-15 HIGH 7.8 CVE-2026-40499 radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute… Radare2 after 6.1.4 Fix from $1,9502026-04-15 HIGH 7.8 CVE-2026-33414 Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine b… Podman 5.8.2+ Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-35196 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/i… Chamilo Lms after 1.11.38 Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-24893 openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contai… Openitcockpit 5.5.2+ Fix from $1,9502026-04-14 CRITICAL 9.8 CVE-2026-39808 KEVEPSS 91% A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4… Fortisandbox after 4.4.9 Fix from $2,3002026-04-14