Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-40288 PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to … Praisonaiagents 1.5.140 / 4.5.139+ Fix from $2,3002026-04-14 HIGH 7.4 CVE-2026-39420 MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated … Maxkb 2.8.0+ Fix from $1,9502026-04-14 MEDIUM 5.5 CVE-2026-39417 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execu… Maxkb 2.8.0+ Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-6195EPSS 14% A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the fil… Mitigation only Fix from $2,3002026-04-13 HIGH 8.1 CVE-2026-28291 simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git… Simple Git 3.32.0+ Fix from $1,9502026-04-13 HIGH 7.2 CVE-2026-34188 Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue … Pandora Fms 800.1+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2026-30806 Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pa… Pandora Fms 800.1+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2026-30809 Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affe… Pandora Fms 800.1+ Fix from $1,9502026-04-13 HIGH 7.2 CVE-2026-6204EPSS 8% LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the N… Librenms 26.3.0+ Fix from $1,9502026-04-13 HIGH 7.3 CVE-2026-6158 A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of t… Mitigation only Fix from $1,9502026-04-13 CRITICAL 9.8 CVE-2026-6155 A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6156 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cst… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6154 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6139 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6140 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of … Mitigation only Fix from $2,3002026-04-13 MEDIUM 6.3 CVE-2026-6141 A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/To… Patch available Fix from $1,6002026-04-13 CRITICAL 9.8 CVE-2026-6138 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6131 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6132 A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecg… Mitigation only Fix from $2,3002026-04-12 HIGH 7.3 CVE-2026-6130 A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.… Mitigation only Fix from $1,9502026-04-12 CRITICAL 9.8 CVE-2026-6116 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6115 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6113 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg … Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6114 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cste… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6112 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the… Mitigation only Fix from $2,3002026-04-12 MEDIUM 6.3 CVE-2026-6108 A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/m… Mitigation only Fix from $1,6002026-04-12 CRITICAL 9.8 CVE-2026-5058 aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… Mitigation only Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-5059 aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on… Mitigation only Fix from $2,3002026-04-11 HIGH 7.5 CVE-2026-4157 ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to e… Home Flex Cph50 Firmware 5.5.4.22+ Fix from $1,9502026-04-11 HIGH 8.8 CVE-2026-32892 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file … Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10